Lucene search

K
cvelistMitreCVELIST:CVE-2019-7331
HistoryFeb 04, 2019 - 7:00 p.m.

CVE-2019-7331

2019-02-0419:00:00
mitre
www.cve.org
9
cve-2019-7331
cross site scripting
zoneminder
html injection
xss attack

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

37.8%

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named “signal check color” (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

37.8%