CVE-2019-7331
published 2019-02-04CVE-2019-7331: Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php)…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.90%
55.4th percentile
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.34.6-1 (bookworm) | zoneminder 1.34.6-1 (bookworm) |
| zoneminder | zoneminder | <= 1.32.3 | — |
| zoneminder | zoneminder | >= 0 < 1.34.6-1 | 1.34.6-1 |
| zoneminder | zoneminder | >= 0 < 1.34.6-1 | 1.34.6-1 |
| zoneminder | zoneminder | >= 0 < 1.34.6-1 | 1.34.6-1 |
| zoneminder | zoneminder | >= 0 < 1.34.6-1 | 1.34.6-1 |
| zoneminder | zoneminder | >= 0 < 1.29.0+dfsg-1ubuntu2+esm1 | 1.29.0+dfsg-1ubuntu2+esm1 |
| zoneminder | zoneminder | >= 0 < 1.32.3-2ubuntu2+esm1 | 1.32.3-2ubuntu2+esm1 |
| zoneminder | zoneminder | >= 0 < 1.36.12+dfsg1-1ubuntu0.1~esm1 | 1.36.12+dfsg1-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
zoneminder vulnerabilities
osv·2023-02-27·CVSS 6.1
CVE-2019-6777 [MEDIUM] zoneminder vulnerabilities
zoneminder vulnerabilities
It was discovered that ZoneMinder was not properly sanitizing URL
parameters for certain views. An attacker could possibly use this issue to
perform a cross-site scripting (XSS) attack. This issue was only fixed in
Ubuntu 16.04 ESM. (CVE-2019-6777)
It was discovered that ZoneMinder was not properly sanitizing stored user
input later printed to the user in certain views. An attacker could
possibly use this issue to perform a cross-site scripting (XSS) attack.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2019-6990,
CVE-2019-6992)
It was discovered that ZoneMinder was not properly limiting data size and
not properly performing bound checks when processing username and password
data, which could lead to a stack buffer overflow. An attacker could
possibly us
GHSA
GHSA-24p7-v3fm-63vm: Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1
ghsa_unreviewed·2022-05-14
CVE-2019-7331 [MEDIUM] CWE-79 GHSA-24p7-v3fm-63vm: Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
OSV
CVE-2019-7331: Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1
osv·2019-02-04·CVSS 6.1
CVE-2019-7331 [MEDIUM] CVE-2019-7331: Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
Ubuntu
ZoneMinder vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 6.1
CVE-2019-7332 [MEDIUM] ZoneMinder vulnerabilities
Title: ZoneMinder vulnerabilities
Summary: Several security issues were fixed in ZoneMinder.
It was discovered that ZoneMinder was not properly sanitizing URL
parameters for certain views. An attacker could possibly use this issue to
perform a cross-site scripting (XSS) attack. This issue was only fixed in
Ubuntu 16.04 ESM. (CVE-2019-6777)
It was discovered that ZoneMinder was not properly sanitizing stored user
input later printed to the user in certain views. An attacker could
possibly use this issue to perform a cross-site scripting (XSS) attack.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2019-6990,
CVE-2019-6992)
It was discovered that ZoneMinder was not properly limiting data size and
not properly performing bound checks when processing username and password
data, which c
Debian
CVE-2019-7331: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 whi...
vendor_debian·2019·CVSS 6.1
CVE-2019-7331 [MEDIUM] CVE-2019-7331: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 whi...
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
Scope: local
bookworm: resolved (fixed in 1.34.6-1)
bullseye: resolved (fixed in 1.34.6-1)
forky: resolved (fixed in 1.34.6-1)
sid: resolved (fixed in 1.34.6-1)
trixie: resolved (fixed in 1.34.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-04
Published