CVE-2019-7351Injection in Zoneminder

CWE-74Injection4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 51.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateMay 14

Description

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8937-h2h2-h5rj: Log Injection exists in ZoneMinder through 12022-05-14
OSV
CVE-2019-7351: Log Injection exists in ZoneMinder through 12019-02-04

📋Vendor Advisories

1
Debian
CVE-2019-7351: zoneminder - Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the...2019