CVE-2017-5368 Details
Description
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/bugtraq/2017/Feb/6 | CVE | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2017/Feb/11 | CVE | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96126 | CVE | |
| http://seclists.org/bugtraq/2017/Feb/6 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2017/Feb/11 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96126 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zoneminder zoneminder | 1.29.0 1.30.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 10, 2017 | CVE Modified | [email protected] |
| Feb 9, 2017 | Reanalysis | [email protected] |
| Feb 8, 2017 | Initial Analysis | [email protected] |