Stored Cross Site Scripting Vulnerability in ZoneMinder by ZoneMinder
CVE-2022-30768
5.4MEDIUM
What is CVE-2022-30768?
A Stored Cross Site Scripting (XSS) vulnerability in ZoneMinder version 1.36.12 allows an attacker to inject and execute malicious HTML or JavaScript code through the Username field. This occurs when the Logout action is performed by an Admin or non-Admin users who have access to view logged-in users. This vulnerability poses a risk, enabling potential attackers to compromise the integrity of the application. It is crucial to note that this issue arises in later versions beyond CVE-2019-7348 and employs a different method of attack.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved