PT-2022-24869 · Unknown+2 · Zoneminder+2

Published

2022-10-07

·

Updated

2023-11-30

·

CVE-2022-39285

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.36.27 ZoneMinder versions prior to 1.37.24
Description The file parameter in ZoneMinder is vulnerable to a cross-site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This allows a malicious user to provide code that will execute when a user views the specific log on the "view=log" page. The vulnerability enables an attacker to store code within the logs that will be executed when loaded by a legitimate user, potentially leading to data loss and/or further exploitation, including account takeover.
Recommendations For versions prior to 1.36.27, upgrade to version 1.36.27 or later. For versions prior to 1.37.24, upgrade to version 1.37.24 or later. As a temporary workaround for users unable to upgrade, disable database logging to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2858
ALT-PU-2022-2978
ALT-PU-2023-7284
CVE-2022-39285
GHSA-H6XP-CVWV-Q433

Affected Products

Alt Linux
Debian
Zoneminder