CVE-2019-7352
6.1
MEDIUM
CVSS 3.1
EPSS 0.24%
Description
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code.
How to fix CVE-2019-7352
To remediate CVE-2019-7352, upgrade the affected package to a fixed version below.
- Debian/zoneminder—upgrade to 1.34.6-1 or later
Is CVE-2019-7352 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.34.6-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |