Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-57834
HistoryApr 01, 2022 - 12:00 a.m.

ZoneMinder Cross-Site Scripting Vulnerability (CNVD-2022-57834)

2022-04-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
zoneminder
video surveillance
cross-site scripting
vulnerability
remote attackers
malicious scripts

EPSS

0.001

Percentile

37.8%

ZoneMinder is an open source video surveillance software system. The system supports IP, USB and analog cameras, etc. A cross-site scripting vulnerability exists in ZoneMinder 1.32.3 and prior versions, which stems from the fact that the program does not validate input or filter output, and can be exploited by remote attackers to inject malicious scripts into a page and execute the script in the user’s browser.