CVE-2019-7331
6.1
MEDIUM
CVSS 3.1
EPSS 0.24%
Description
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
How to fix CVE-2019-7331
To remediate CVE-2019-7331, upgrade the affected package to a fixed version below.
- Debian/zoneminder—upgrade to 1.34.6-1 or later
Is CVE-2019-7331 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.34.6-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |