CVE-2019-7345: XSS
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEBTITLE, HOMEURL, HOMECONTENT, or WEBCONSOLEBANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7345?
The severity of CVE-2019-7345 is medium.
What is CVE-2019-7345?
CVE-2019-7345 is a vulnerability that allows for Self-Stored Cross Site Scripting (XSS) attacks in ZoneMinder through version 1.32.3.
How does CVE-2019-7345 work?
CVE-2019-7345 allows an attacker to execute HTML or JavaScript code by exploiting the lack of input validation in the view options of ZoneMinder.
How can I fix CVE-2019-7345?
To fix CVE-2019-7345, upgrade ZoneMinder to a version beyond 1.32.3 that includes input validation for the affected values.
Are there any references for CVE-2019-7345?
Yes, you can find more information about CVE-2019-7345 at the following link: [ZoneMinder GitHub Issue #2468](https://github.com/ZoneMinder/zoneminder/issues/2468)