VDB

CVE-2019-7337

CVE-2019-7337 PUBLISHED CVSS 4.800000190734863 MEDIUM

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

EPSS 0.68% · 50.0th percentile

Risk Scores

CVSS 3.0
4.800000190734863
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.68%
50.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSzoneminder0, 1.32.3-2build1, 1.32.3-2ubuntu1
Ubuntu:Pro:16.04:LTSzoneminder1.28.1-8, 1.29.0+dfsg-1, 1.29.0+dfsg-1ubuntu1
Ubuntu:24.04:LTSzoneminder0, 1.36.33+dfsg1-1build1, 1.36.33+dfsg1-1build4
Ubuntu:Pro:22.04:LTSzoneminder0, 1.36.7+dfsg1-1, 1.36.11+dfsg1-1
Ubuntu:25.10zoneminder0, *

Timeline

  • Feb 4, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›