Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zoneminder zoneminder |