Lucene search

K
osvGoogleOSV:CVE-2019-7331
HistoryFeb 04, 2019 - 7:29 p.m.

CVE-2019-7331

2019-02-0419:29:00
Google
osv.dev
11

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

37.8%

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named “signal check color” (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

37.8%