+33 (0)1 8695 8660

Vulnerability Details :

An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
Publish Date : 2019-01-24 Last Update Date : 2019-01-24

- CVSS Scores & Vulnerability Types

CVSS Score
4.3
Confidentiality Impact None(There is no impact to the confidentiality of the system.)
Integrity Impact Partial(Modification of some system files or information is possible, but the attacker does not have control over what can be modified, or the scope of what the attacker can affect is limited.)
Availability Impact None(There is no impact to the availability of the system.)
Access Complexity Medium(The access conditions are somewhat specialized. Some preconditions must be satistified to exploit)
Authentication Not required(Authentication is not required to exploit the vulnerability.)
Gained Access None
Vulnerability Type(s) Cross Site Scripting
CWE ID 79

- Products Affected By CVE-2019-6777

# Product Type Vendor Product Version Update Edition Language
1 Application Zoneminder Zoneminder 1.32.3 Version Details Vulnerabilities

- Number Of Affected Versions By Product

Vendor Product Vulnerable Versions
Zoneminder Zoneminder 1

- References For CVE-2019-6777

https://github.com/mnoorenberghe/ZoneMinder/commit/59cc65411f02c7e39a270fda3ecb4966d7b48d41
https://github.com/ZoneMinder/zoneminder/issues/2436

- Metasploit Modules Related To CVE-2019-6777

There are not any metasploit modules related to this CVE entry (Please visit www.metasploit.com for more information)


Newsletter Cybersécurité

Restez informé: recevez régulièrement les nouveautés et évènements en matière de cybersécurité et sécurité informatique.
En renseignant votre adresse email, vous acceptez de recevoir nos derniers articles de blog par courrier électronique et vous prenez connaissance de notre Politique de Confidentialité. Vous pouvez vous désinscrire à tout moment.

Notre expertise cybersécurité validée par de multiples certifications internationales

certifications sécurité informatique AKAOMA