CVE-2022-30769: Medium severity zoneminder vulnerability
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30769?
CVE-2022-30769 is a vulnerability in ZoneMinder through version 1.36.12 that allows an attacker to poison a session cookie to the next logged-in user.
What is the severity of CVE-2022-30769?
The severity of CVE-2022-30769 is medium with a CVSS score of 4.6.
How does CVE-2022-30769 affect ZoneMinder?
CVE-2022-30769 affects ZoneMinder up to version 1.36.12 and allows an attacker to perform session fixation by poisoning a session cookie to the next logged-in user.
What is session fixation?
Session fixation is a type of attack where an attacker sets the session identifier of a victim to a known value, allowing the attacker to assume the victim's identity.
How can I fix CVE-2022-30769?
To fix CVE-2022-30769, it is recommended to update ZoneMinder to a version higher than 1.36.12, which includes the necessary security patches.