CVE-2024-43359: Zoneminder
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61.
Affected products
- Zoneminder Zoneminder: before 1.36.34 (fixed in 1.36.34); from 1.37.00, before 1.37.61 (fixed in 1.37.61)
Published 2024-08-12. Last modified 2026-06-17.