Cross-site scripting in ZoneMinder - #VU153364
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the application origin.
The vulnerability exists due to improper neutralization of the nested filter identifier in web/skins/classic/views/filter.php and web/skins/classic/views/js/filter.js.php when rendering a filter page. A remote user can supply a crafted filter URL containing a top-level Id=1, a malicious filter[Id] value, and filter[Query] parameters to execute arbitrary JavaScript in the application origin.
Execution requires an authenticated user with Events View or Edit permission to open the crafted URL. The injected JavaScript runs inside a nonce-authorized script. Cross-site delivery under SameSite Strict was not tested.