Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qch8-8p57-v3gr

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 7 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.

CVSS3: 4.8
nvd
около 7 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.

CVSS3: 4.8
debian
около 7 лет назад

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through ...

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79