Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-57820
HistoryApr 01, 2022 - 12:00 a.m.

ZoneMinder Cross-Site Scripting Vulnerability (CNVD-2022-57820)

2022-04-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
zoneminder
video surveillance
xss vulnerability
remote attacker
html
javascript
parameter
exploit

EPSS

0.001

Percentile

37.8%

ZoneMinder is an open source video surveillance software system. ZoneMinder 1.32.3 and earlier versions have a cross-site scripting vulnerability, which stems from the fact that the program is not properly filtered and a remote attacker can execute HTML or JavaScript code with the help of the ‘filter[Query][terms][0][val]’ parameter. The vulnerability can be exploited to execute HTML or JavaScript code.

EPSS

0.001

Percentile

37.8%