CVE-2020-25729
Publication date 17 September 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| zoneminder | ||
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release |
Notes
ccdm94
this vulnerability seems to have been introduced with commits 24a5b78f4c and 05f0338219. These commits are not present in xenial's, nor in focal's zoneminder packages.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.1 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N