Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7346

Опубликовано: 04 фев. 2019
Источник: debian

Описание

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderfixed1.34.6-1package

Примечания

  • https://github.com/ZoneMinder/zoneminder/issues/2469

  • https://github.com/ZoneMinder/zoneminder/commit/dbc1c7b72f8cab5094a4a498a66ca2c0d3f29872

  • See README.Debian.security, only supported behind an authenticated HTTP zone

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

CVSS3: 8.8
nvd
около 7 лет назад

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

CVSS3: 8.8
github
больше 3 лет назад

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.