cve/2022/CVE-2022-30768.md
2024-06-18 02:51:15 +02:00

840 B

CVE-2022-30768

Description

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.

POC

Reference

Github

No PoCs found on GitHub currently.