CVE-2019-7346: Zoneminder

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

Affected products

Published 2019-02-04. Last modified 2026-06-17.