Unrated severityOSV Advisory· Published Feb 4, 2019· Updated Sep 16, 2024
CVE-2019-7345
CVE-2019-7345
Description
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21.32.3, v1.25, v1.26.0, …+ 1 more
- (no CPE)range: 1.32.3, v1.25, v1.26.0, …
- (no CPE)range: <=1.32.3
Patches
Vulnerability mechanics
References
1- github.com/ZoneMinder/zoneminder/issues/2468mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.