Closed
Description
Describe Your Environment
- ZoneMinder v1.33.1
- Installed from - ppa:iconnor/zoneminder-master
Describe the bug
The view download, while exporting an event file, prints the Exportfile parameter value on the webpage without applying any proper filtration, leading to reflected XSS.
To Reproduce
Affected URL :
http://localhost/zm/index.php?view=download&eid=1&exportFile=javascript:alert('1');`&generated=1
Payload used - javascript:alert('1');
- Navigate to the Affected URL
- Click on Download, Payload would be triggered.
Expected behavior
- Proper escaping of special characters.
Debug Logs
None
