Lucene search

K
cveMitreCVE-2022-30768
HistoryNov 15, 2022 - 10:15 p.m.

CVE-2022-30768

2022-11-1522:15:11
CWE-79
mitre
web.nvd.nist.gov
46
5
cve-2022-30768
stored xss
zoneminder
security vulnerability
cross site scripting
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

37.8%

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

Affected configurations

Nvd
Node
zoneminderzoneminderMatch1.36.12
VendorProductVersionCPE
zoneminderzoneminder1.36.12cpe:2.3:a:zoneminder:zoneminder:1.36.12:*:*:*:*:*:*:*

Social References

More

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

37.8%