Description
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/ZoneMinder/zoneminder/commit/a3e8fd4fd5b579865f35aac3b964bc78d5b7a94a
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/ZoneMinder/zoneminder/issues/2444
Scores
CVSS v3
5.4
EPSS
0.0026
EPSS Percentile
49.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
zoneminder/zoneminder
< 1.32.3
Published
Jan 28, 2019
Tracked Since
Feb 18, 2026