Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7331

Опубликовано: 04 фев. 2019
Источник: debian
EPSS Низкий

Описание

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderfixed1.34.6-1package

Примечания

  • https://github.com/ZoneMinder/zoneminder/issues/2451

  • https://github.com/ZoneMinder/zoneminder/commit/254b7286b4d2654b95080a175c44195667e42ea8

  • See README.Debian.security, only supported behind an authenticated HTTP zone

EPSS

Процентиль: 30%
0.00112
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

CVSS3: 6.1
nvd
больше 6 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

CVSS3: 6.1
github
около 3 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

EPSS

Процентиль: 30%
0.00112
Низкий