CVE-2017-5368
published 2017-02-06CVE-2017-5368: ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make…
PriorityP335high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.05%
60.3th percentile
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.30.4+dfsg-1 (bookworm) | zoneminder 1.30.4+dfsg-1 (bookworm) |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qq57-4v92-3r5q: ZoneMinder v1
ghsa_unreviewed·2022-05-17
CVE-2017-5368 [HIGH] CWE-352 GHSA-qq57-4v92-3r5q: ZoneMinder v1
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
OSV
CVE-2017-5368: ZoneMinder v1
osv·2017-02-06·CVSS 8.8
CVE-2017-5368 [HIGH] CVE-2017-5368: ZoneMinder v1
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
Debian
CVE-2017-5368: zoneminder - ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulne...
vendor_debian·2017·CVSS 8.8
CVE-2017-5368 [HIGH] CVE-2017-5368: zoneminder - ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulne...
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
Scope: local
bookworm: resolved (fixed in 1.30.4+dfsg-1)
bullseye: resolved (fixed in 1.30.4+dfsg-1)
forky: resolved (fixed in 1.30.4+dfsg-1)
sid: resolved (fixed in 1.30.4+dfsg-1)
trixie: res
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-06
Published