vendor:
Zoneminder
by:
Tim Herres
4.3
CVSS
MEDIUM
Zoneminder multiple vulnerabilities
89
CWE
Product Name: Zoneminder
Affected Version From: Zoneminder 1.29
Affected Version To: Zoneminder 1.30
Patch Exists: NO
Related CWE:
CPE: zoneminder
Platforms Tested:
2016
FOXMOLE – Security Advisory 2016-07-05
During an internal code review, multiple vulnerabilities were identified in Zoneminder 1.29 and 1.30. The vulnerabilities include SQL Injection, Cross Site Scripting, Session Fixation, and lack of CSRF Protection. These vulnerabilities could allow a remote attacker to compromise user accounts or access the database.
Mitigation:
Review the entire application for input validation and output encoding.