Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjxc-g8h2-2g9g

Опубликовано: 16 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

CVSS3: 5.4
nvd
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

CVSS3: 5.4
debian
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows ...

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79