CVE Vulnerabilities

CVE-2019-7351

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Feb 04, 2019 | Modified: Feb 04, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the log view page, as demonstrated by the message=User%20admin%20Logged%20in value.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Zoneminder Zoneminder * 1.32.3 (including)
Zoneminder Ubuntu cosmic *
Zoneminder Ubuntu devel *
Zoneminder Ubuntu disco *
Zoneminder Ubuntu eoan *
Zoneminder Ubuntu esm-apps/focal *
Zoneminder Ubuntu esm-apps/jammy *
Zoneminder Ubuntu esm-apps/noble *
Zoneminder Ubuntu esm-apps/xenial *
Zoneminder Ubuntu focal *
Zoneminder Ubuntu groovy *
Zoneminder Ubuntu hirsute *
Zoneminder Ubuntu impish *
Zoneminder Ubuntu jammy *
Zoneminder Ubuntu kinetic *
Zoneminder Ubuntu lunar *
Zoneminder Ubuntu mantic *
Zoneminder Ubuntu noble *
Zoneminder Ubuntu oracular *
Zoneminder Ubuntu trusty *
Zoneminder Ubuntu upstream *
Zoneminder Ubuntu xenial *

Potential Mitigations

References