CVE-2016-10206

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10206
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10206.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-10206
Downstream
Related
Published
2017-03-03T15:59:00Z
Modified
2025-10-14T15:19:48.282727Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php.

References

Affected packages

Git / github.com/zoneminder/zoneminder

Affected ranges

Type
GIT
Repo
https://github.com/zoneminder/zoneminder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v1.*

v1.25
v1.26-beta.1
v1.26-beta.2
v1.26-beta.3
v1.26.0
v1.26.1
v1.26.2
v1.26.3
v1.26.4
v1.26.5
v1.27.0
v1.28.0
v1.29.0
v1.29.0-rc1
v1.29.0-rc2
v1.30.0
v1.30.0-rc1
v1.30.0-rc2