CVE-2024-43359: XSS vulnerabilities in montagereview
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43359?
CVE-2024-43359 is classified as a cross-site scripting vulnerability affecting ZoneMinder.
How do I fix CVE-2024-43359?
To fix CVE-2024-43359, update ZoneMinder to version 1.36.34 or later, or to version 1.37.61 or later.
Which versions of ZoneMinder are affected by CVE-2024-43359?
ZoneMinder versions prior to 1.36.34 and between 1.37.00 and 1.37.61 are affected by CVE-2024-43359.
What parameters are involved in the CVE-2024-43359 vulnerability?
The vulnerability in CVE-2024-43359 is triggered by the displayinterval, speed, and scale parameters in montagereview.
Is CVE-2024-43359 a remote or local vulnerability?
CVE-2024-43359 is a remote vulnerability that can be exploited via crafted requests to ZoneMinder.