CVE-2019-7337
Summary
| CVE | CVE-2019-7337 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-04 19:29:00 UTC |
| Updated | 2019-02-05 21:24:00 UTC |
| Description | Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Reflected Cross Site Scripting(XSS) - events.php · Issue #2456 · ZoneMinder/zoneminder · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 502205 Alpine Linux Security Update for zoneminder
- 505604 Alpine Linux Security Update for zoneminder