First published: Mon Aug 12 2024(Updated: )
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <1.36.34 | |
ZoneMinder | >=1.37.00<1.37.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43359 is classified as a cross-site scripting vulnerability affecting ZoneMinder.
To fix CVE-2024-43359, update ZoneMinder to version 1.36.34 or later, or to version 1.37.61 or later.
ZoneMinder versions prior to 1.36.34 and between 1.37.00 and 1.37.61 are affected by CVE-2024-43359.
The vulnerability in CVE-2024-43359 is triggered by the displayinterval, speed, and scale parameters in montagereview.
CVE-2024-43359 is a remote vulnerability that can be exploited via crafted requests to ZoneMinder.