CVE-2019-8425: XSS
Published Feb 18, 2019
·Updated
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.32.3
Event History
Feb 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-8425?
CVE-2019-8425 is a vulnerability in ZoneMinder before version 1.32.3 that allows for cross-site scripting (XSS) in the construction of SQL-ERR messages.
2
How severe is CVE-2019-8425?
The severity of CVE-2019-8425 is medium, with a severity value of 6.1.
3
What software versions are affected by CVE-2019-8425?
ZoneMinder versions up to and excluding 1.32.3 are affected by CVE-2019-8425.
4
What is the Common Vulnerabilities and Exposures (CVE) reference for CVE-2019-8425?
The Common Vulnerabilities and Exposures (CVE) reference for CVE-2019-8425 is CVE-2019-8425.
5
How can I fix CVE-2019-8425?
To fix CVE-2019-8425, it is recommended to update ZoneMinder to version 1.32.3 or newer.