CVE-2017-5368
Summary
| CVE | CVE-2017-5368 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-06 17:59:00 UTC |
| Updated | 2017-02-10 02:59:00 UTC |
| Description | ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bugtraq: ZoneMinder - multiple vulnerabilities |
MISC |
seclists.org |
Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: ZoneMinder - multiple vulnerabilities |
MISC |
seclists.org |
Exploit, Third Party Advisory, VDB Entry |
| ZoneMinder CVE-2017-5368 Cross Site Request Forgery Vulnerability |
BID |
www.securityfocus.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501341 Alpine Linux Security Update for zoneminder
- 505603 Alpine Linux Security Update for zoneminder