Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prfp-rc42-5739

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

EPSS

Процентиль: 55%
0.00321
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

CVSS3: 4.8
nvd
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

CVSS3: 4.8
debian
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32 ...

EPSS

Процентиль: 55%
0.00321
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79