PT-2019-18550 · Zoneminder+1 · Zoneminder+1
Loginsoft-Research
·
Publicado
2019-02-04
·
Atualizado
2020-02-17
·
CVE-2019-7345
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZoneMinder versions prior to 1.33
Description
A Self-Stored Cross Site Scripting (XSS) issue exists due to the lack of input validation for the
WEB TITLE, HOME URL, HOME CONTENT, or WEB CONSOLE BANNER values in the 'options' view (options.php), allowing an attacker to execute HTML or JavaScript code. This issue relates to the functions.php file.Recommendations
For ZoneMinder versions prior to 1.33, update to a version that includes input validation for the
WEB TITLE, HOME URL, HOME CONTENT, and WEB CONSOLE BANNER values to prevent XSS attacks. As a temporary workaround, consider restricting access to the 'options' view (options.php) until a patch is available.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Zoneminder