Session Fixation Vulnerability in ZoneMinder Affecting Multiple Versions
CVE-2019-7350
7.3HIGH
What is CVE-2019-7350?
ZoneMinder has a vulnerability allowing session fixation, affecting versions up to 1.32.3. An attacker can manipulate session cookies to gain unauthorized access to a victim's account. This is due to the generation of multiple overlapping cookies during user logins, enabling the attacker to fixate their session and hijack subsequent logins of the targeted user. Protect your ZoneMinder installation by implementing necessary security measures.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published