PT-2022-24873 · Unknown+2 · Zoneminder+2
Published
2022-10-07
·
Updated
2023-11-30
·
CVE-2022-39290
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZoneMinder versions prior to the fixed version
Description
The issue allows authenticated users to bypass CSRF keys by modifying the request supplied to the ZoneMinder web application. This can be done by replacing HTTP POST with an HTTP GET and removing the CSRF key from the request. An attacker can use an HTTP GET request to perform actions with no CSRF protection, potentially causing an authenticated user to perform unexpected actions on the web application.
Recommendations
Upgrade to a version that includes the fix for this issue as soon as possible.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Zoneminder