Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32292
HistorySep 30, 2021 - 5:56 a.m.

Cross-site Scripting (XSS)

2021-09-3005:56:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
cross-site scripting
zoneminder:edge
download.php
html
javascript
filtration
vulnerable

EPSS

0.001

Percentile

37.8%

zoneminder:edge is vulnerable to cross site scripting (XSS). An attacker is able to execute HTML or JavaScript code via a vulnerable ‘eid’ (aka Event ID) parameter value in the view download (download.php) because proper filtration is omitted.