CVE-2019-13072

Priority
Description
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a
malicious user to embed and execute JavaScript code in the browser of any
user who navigates to this page.
Ubuntu-Description
msalvatore> Based on the commit that resolves this, it's likely a duplicate of CVE-2019-7344.
Notes
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 20.04 LTS (Focal Fossa):needed
Ubuntu 20.10 (Groovy Gorilla):needed
More Information

Updated: 2020-07-28 18:54:36 UTC (commit 7b6828437fde0509248708fcdb5b0f7587b85bd1)