First published: Tue Nov 15 2022(Updated: )
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | =1.36.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-30768.
The severity of CVE-2022-30768 is medium with a CVSS score of 5.4.
The affected software version is ZoneMinder 1.36.12.
An attacker can exploit this vulnerability by executing HTML or JavaScript code through the Username field when an Admin or non-Admin user clicks on Logout.
To mitigate this vulnerability, users should upgrade to a version later than 1.36.12.