Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-30768
HistoryNov 15, 2022 - 12:00 a.m.

CVE-2022-30768

2022-11-1500:00:00
ubuntu.com
ubuntu.com
18
zoneminder
cross site scripting
xss
security issue
user logout
attack method
html
javascript
username field.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

37.8%

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an
attacker to execute HTML or JavaScript code via the Username field when an
Admin (or non-Admin users that can see other users logged into the
platform) clicks on Logout. NOTE: this exists in later versions than
CVE-2019-7348 and requires a different attack method.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

37.8%