Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25825

Опубликовано: 25 фев. 2023
Источник: nvd
CVSS3: 7.7
CVSS3: 6.1
EPSS Низкий

Описание

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patched in version 1.36.33.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
Версия до 1.36.33 (исключая)
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
Версия от 1.37.0 (включая) до 1.37.33 (исключая)

EPSS

Процентиль: 75%
0.00894
Низкий

7.7 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 3 года назад

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patched in version 1.36.33.

CVSS3: 7.7
debian
почти 3 года назад

ZoneMinder is a free, open source Closed-circuit television software a ...

EPSS

Процентиль: 75%
0.00894
Низкий

7.7 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79