Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-57838
HistoryApr 01, 2022 - 12:00 a.m.

ZoneMinder Cross-Site Scripting Vulnerability (CNVD-2022-57838)

2022-04-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
zoneminder
video surveillance
cross-site scripting
vulnerability
remote attackers
html
javascript
host parameter

EPSS

0.001

Percentile

37.8%

ZoneMinder is an open source video surveillance software system. ZoneMinder 1.32.3 and earlier versions have a cross-site scripting vulnerability, which stems from the fact that the program is not properly filtered and can be exploited by remote attackers to execute arbitrary HTML or JavaScript with the help of the ‘Host’ parameter. code with the ‘Host’ parameter.