Описание
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| cosmic | ignored | end of life |
| devel | not-affected | 1.36.32+dfsg1-1 |
| disco | ignored | end of life |
| eoan | ignored | end of life |
| esm-apps/focal | released | 1.32.3-2ubuntu2+esm1 |
| esm-apps/jammy | not-affected | 1.36.12+dfsg1-1 |
| esm-apps/noble | not-affected | 1.36.32+dfsg1-1 |
| esm-apps/xenial | released | 1.29.0+dfsg-1ubuntu2+esm1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32 ...
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3