Vulnerability Description
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoneminder | Zoneminder | 1.32.3 |
Related Weaknesses (CWE)
References
- https://github.com/ZoneMinder/zoneminder/issues/2436ExploitIssue TrackingThird Party Advisory
- https://github.com/mnoorenberghe/ZoneMinder/commit/59cc65411f02c7e39a270fda3ecb4PatchThird Party Advisory
- https://github.com/ZoneMinder/zoneminder/issues/2436ExploitIssue TrackingThird Party Advisory
- https://github.com/mnoorenberghe/ZoneMinder/commit/59cc65411f02c7e39a270fda3ecb4PatchThird Party Advisory
FAQ
What is CVE-2019-6777?
CVE-2019-6777 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
How severe is CVE-2019-6777?
CVE-2019-6777 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6777?
Check the references section above for vendor advisories and patch information. Affected products include: Zoneminder Zoneminder.