Vulnerability Description
Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set of multiple cookies (between 3 and 5) is being generated when a user successfully logs in, and these sets overlap for successive logins.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoneminder | Zoneminder | <= 1.32.3 |
Related Weaknesses (CWE)
References
- https://github.com/ZoneMinder/zoneminder/issues/2471ExploitThird Party Advisory
- https://github.com/ZoneMinder/zoneminder/issues/2471ExploitThird Party Advisory
FAQ
What is CVE-2019-7350?
CVE-2019-7350 is a vulnerability with a CVSS score of 7.3 (HIGH). Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set of...
How severe is CVE-2019-7350?
CVE-2019-7350 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-7350?
Check the references section above for vendor advisories and patch information. Affected products include: Zoneminder Zoneminder.