Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-25825
HistoryFeb 25, 2023 - 1:15 a.m.

Cross site scripting

2023-02-2501:15:00
PRIOn knowledge base
www.prio-n.com
6
zoneminder
cctv
xss
vulnerability
database logs
web ui
patch
version 1.36.33

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.7%

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patched in version 1.36.33.

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.7%