CVE-2020-25730: XSS
Published Apr 4, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHPSELF component in classic/views/download.php.
Affected Software
2 affected components
ZoneMinder Zoneminder<1.34.21
ZoneMinder Zoneminder<1.34.21
Remediation
Event History
Apr 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-25730?
CVE-2020-25730 is classified as a critical vulnerability due to its potential for remote code execution and privilege escalation.
2
How do I fix CVE-2020-25730?
To mitigate CVE-2020-25730, upgrade ZoneMinder to version 1.34.21 or later.
3
What are the potential impacts of CVE-2020-25730?
The potential impacts of CVE-2020-25730 include unauthorized access to sensitive information and the execution of arbitrary code.
4
Who is affected by CVE-2020-25730?
CVE-2020-25730 affects users of ZoneMinder versions prior to 1.34.21.
5
What type of vulnerability is CVE-2020-25730?
CVE-2020-25730 is a Cross Site Scripting (XSS) vulnerability.