CVE-2019-7352
Summary
| CVE | CVE-2019-7352 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-04 19:29:00 UTC |
| Updated | 2019-02-04 20:13:00 UTC |
| Description | Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Self - Stored Cross Site Scripting (XSS) - state.php · Issue #2475 · ZoneMinder/zoneminder · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 502205 Alpine Linux Security Update for zoneminder
- 505604 Alpine Linux Security Update for zoneminder