VDB

CVE-2019-7337

CVE-2019-7337 PUBLISHED

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

EPSS 0.23% · 46.5th percentile

Risk Scores

EPSS Score
0.23%
46.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSzoneminder0, 1.32.3-2build1, 1.32.3-2ubuntu1
Ubuntu:Pro:16.04:LTSzoneminder1.28.1-8, 1.29.0+dfsg-1, 1.29.0+dfsg-1ubuntu1
Ubuntu:24.04:LTSzoneminder0, 1.36.33+dfsg1-1build1, 1.36.33+dfsg1-1build4
Ubuntu:Pro:22.04:LTSzoneminder0, 1.36.7+dfsg1-1, 1.36.11+dfsg1-1
Ubuntu:25.10zoneminder0, *

Timeline

  • Feb 4, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›