First published: Thu Apr 04 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <1.34.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25730 is classified as a critical vulnerability due to its potential for remote code execution and privilege escalation.
To mitigate CVE-2020-25730, upgrade ZoneMinder to version 1.34.21 or later.
The potential impacts of CVE-2020-25730 include unauthorized access to sensitive information and the execution of arbitrary code.
CVE-2020-25730 affects users of ZoneMinder versions prior to 1.34.21.
CVE-2020-25730 is a Cross Site Scripting (XSS) vulnerability.