Self – Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable ‘username’ parameter value in the view user (user.php) because proper filtration is omitted.
CWE-79
CVE-2019-7349
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable ‘newMonitor[V4LCapturesPerFrame]’ parameter value in the view monitor (monitor.php) because proper filtration is omitted.
CVE-2019-7352
Self – Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view ‘state’ (aka Run State) (state.php) does no input validation to the value supplied to the ‘New State’ (aka newState) field, allowing an attacker to execute HTML or JavaScript code.
CVE-2019-7356
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
CVE-2019-7295
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
CVE-2019-7296
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
