CVE-2020-25729: XSS
Published Sep 17, 2020
·Updated
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.34.21
Remediation
Event History
Sep 17, 2020
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this ZoneMinder vulnerability?
The vulnerability ID for this ZoneMinder vulnerability is CVE-2020-25729.
2
What is the severity of CVE-2020-25729?
The severity of CVE-2020-25729 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2020-25729?
The affected software for CVE-2020-25729 is Zoneminder Zoneminder version up to exclusive 1.34.21.
4
How can this vulnerability be exploited?
This vulnerability can be exploited via the connkey parameter to download.php or export.php, allowing for cross-site scripting (XSS) attacks.
5
How can I fix CVE-2020-25729?
To fix CVE-2020-25729, update ZoneMinder to version 1.34.21 or later.