First published: Mon Feb 04 2019(Updated: )
Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set of multiple cookies (between 3 and 5) is being generated when a user successfully logs in, and these sets overlap for successive logins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | <=1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7350 is a session fixation vulnerability in ZoneMinder through 1.32.3 which allows an attacker to hijack the victim's account by fixing their own session cookies.
The severity of CVE-2019-7350 is high with a CVSS score of 7.3.
The session fixation vulnerability in ZoneMinder occurs because multiple cookies are generated when a user logs in, allowing an attacker to fixate their own session cookies to hijack the victim's account.
ZoneMinder version 1.32.3 is affected by CVE-2019-7350.
To mitigate the session fixation vulnerability in ZoneMinder, it is recommended to update to a version higher than 1.32.3 where the issue has been fixed.