CVE-2019-7346: CSRF
Published Feb 4, 2019
·Updated
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7346?
CVE-2019-7346 is a CSRF check issue that exists in ZoneMinder through 1.32.3.
2
What is the severity of CVE-2019-7346?
The severity of CVE-2019-7346 is high with a CVSS score of 8.8.
3
How does CVE-2019-7346 affect ZoneMinder?
CVE-2019-7346 allows CSRF attacks to be successful in ZoneMinder through 1.32.3.
4
How can I fix CVE-2019-7346?
To fix CVE-2019-7346, upgrade to a version of ZoneMinder that is not affected, or apply the necessary security patches.
5
Where can I find more information about CVE-2019-7346?
You can find more information about CVE-2019-7346 in the following link: https://github.com/ZoneMinder/zoneminder/issues/2469