MEDIUM
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code
Published Feb 4, 2019
4.8
MEDIUMCVSS 3.0
EPSS 0.67%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.