PT-2017-16456 · Zoneminder+1 · Zoneminder+1
Published
2017-02-06
·
Updated
2017-06-13
·
CVE-2017-5367
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZoneMinder versions 1.29 through 1.30
Description
Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder, an open-source CCTV server web application. This allows a remote attacker to execute malicious scripts within an authenticated client's browser. The URL is /zm/index.php and sample parameters could include
action=login, view=postlogin, view=console, view=groups, view=events&filter[terms][1][cnj]=and, and view=events&limit=1.Recommendations
For ZoneMinder version 1.29, update to a version that fixes the reflected XSS vulnerabilities.
For ZoneMinder version 1.30, update to a version that fixes the reflected XSS vulnerabilities.
As a temporary workaround, consider restricting access to the vulnerable parameters, such as
view and filter[terms][1][cnj], until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Zoneminder