CVE-2022-30768: XSS
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-30768.
What is the severity of CVE-2022-30768?
The severity of CVE-2022-30768 is medium with a CVSS score of 5.4.
What is the affected software version?
The affected software version is ZoneMinder 1.36.12.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing HTML or JavaScript code through the Username field when an Admin or non-Admin user clicks on Logout.
Is there a fix available for CVE-2022-30768?
To mitigate this vulnerability, users should upgrade to a version later than 1.36.12.