CVE-2019-7351: Medium severity ZoneMinder Zoneminder vulnerability
Published Feb 4, 2019
·Updated
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Log Injection vulnerability?
The vulnerability ID for this Log Injection vulnerability is CVE-2019-7351.
2
What is the severity of CVE-2019-7351?
The severity of CVE-2019-7351 is medium with a CVSS score of 6.5.
3
How does Log Injection occur in ZoneMinder?
Log Injection occurs in ZoneMinder when an attacker tricks a victim into visiting a specially crafted link that injects a customized log message.
4
Which version of ZoneMinder is affected by CVE-2019-7351?
ZoneMinder versions up to and including 1.32.3 are affected by CVE-2019-7351.
5
Is there a fix available for CVE-2019-7351?
Yes, upgrading to a version later than 1.32.3 of ZoneMinder resolves the Log Injection vulnerability.