PT-2022-24873 · Unknown+2 · Zoneminder+2

Published

2022-10-07

·

Updated

2023-11-30

·

CVE-2022-39290

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to the fixed version
Description The issue allows authenticated users to bypass CSRF keys by modifying the request supplied to the ZoneMinder web application. This can be done by replacing HTTP POST with an HTTP GET and removing the CSRF key from the request. An attacker can use an HTTP GET request to perform actions with no CSRF protection, potentially causing an authenticated user to perform unexpected actions on the web application.
Recommendations Upgrade to a version that includes the fix for this issue as soon as possible. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2858
ALT-PU-2022-2978
ALT-PU-2023-7284
CVE-2022-39290
GHSA-XGV6-QV6C-399Q

Affected Products

Alt Linux
Debian
Zoneminder