CVE-2023-25825

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/02/2023
Last modified:
07/11/2023

Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patched in version 1.36.33.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* 1.36.33 (excluding)
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* 1.37.0 (including) 1.37.33 (excluding)