Cross-site Scripting (XSS) Affecting zoneminder package, versions <1.36.7-r0
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALPINE317-ZONEMINDER-3144681
- published 25 Nov 2021
- disclosed 4 Feb 2019
How to fix?
Upgrade Alpine:3.17
zoneminder
to version 1.36.7-r0 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream zoneminder
package and not the zoneminder
package as distributed by Alpine
.
See How to fix?
for Alpine:3.17
relevant fixed versions and status.
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view _monitor_filters.php contains takes in input from the user and saves it into the session, and retrieves it later (insecurely). The values of the MonitorName and Source parameters are being displayed without any output filtration being applied. This relates to the view=cycle value.