Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-30768

Опубликовано: 15 нояб. 2022
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zoneminder:zoneminder:1.36.12:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

CVSS3: 5.4
debian
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows ...

CVSS3: 5.4
github
около 3 лет назад

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79