First published: Tue Nov 15 2022(Updated: )
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | <=1.36.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30769 is a vulnerability in ZoneMinder through version 1.36.12 that allows an attacker to poison a session cookie to the next logged-in user.
The severity of CVE-2022-30769 is medium with a CVSS score of 4.6.
CVE-2022-30769 affects ZoneMinder up to version 1.36.12 and allows an attacker to perform session fixation by poisoning a session cookie to the next logged-in user.
Session fixation is a type of attack where an attacker sets the session identifier of a victim to a known value, allowing the attacker to assume the victim's identity.
To fix CVE-2022-30769, it is recommended to update ZoneMinder to a version higher than 1.36.12, which includes the necessary security patches.