Session Fixation Vulnerability in ZoneMinder Affecting Multiple Versions
CVE-2019-7350

7.3HIGH

Key Information:

Vendor

Zoneminder

Vendor
CVE Published:
4 February 2019

What is CVE-2019-7350?

ZoneMinder has a vulnerability allowing session fixation, affecting versions up to 1.32.3. An attacker can manipulate session cookies to gain unauthorized access to a victim's account. This is due to the generation of multiple overlapping cookies during user logins, enabling the attacker to fixate their session and hijack subsequent logins of the targeted user. Protect your ZoneMinder installation by implementing necessary security measures.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.