Lucene search

K
nvd[email protected]NVD:CVE-2022-30768
HistoryNov 15, 2022 - 10:15 p.m.

CVE-2022-30768

2022-11-1522:15:11
CWE-79
web.nvd.nist.gov
6
stored cross site scripting
zoneminder
cve-2022-30768
html
javascript
admin
logout

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

37.8%

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

Affected configurations

Nvd
Node
zoneminderzoneminderMatch1.36.12
VendorProductVersionCPE
zoneminderzoneminder1.36.12cpe:2.3:a:zoneminder:zoneminder:1.36.12:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

37.8%