Files
zoneminder/web/views
Isaac Connor fc994830e7 fix: require a CSRF token for image proxy requests
index.php skips csrf_check() for view=image because images are loaded
through <img src>, and csrf_check() only validates POSTs in any case. The
proxy= handler makes the server fetch a caller-supplied URL, so a page
on another site could embed an <img> pointing at it and have a logged-in
monitor editor's browser drive server-side requests to the LAN.

When ZM_ENABLE_CSRF_MAGIC is on, the proxy branch now checks
__csrf_magic from the request with csrf_check_tokens() and answers 403
without it. Plain image views are unaffected. The only caller, the
camera discovery thumbnail on add_monitors, appends csrfMagicName and
csrfMagicToken to its <img> URL, and now URL-encodes the camera stream
URL so a stream URL containing & or " no longer truncates the proxy
parameter or breaks out of the src attribute.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 2958f89c5af63040483ac8a389d1fd7080b777a7)
2026-09-24 23:16:11 -04:00
..
2021-08-18 10:53:59 -04:00
2021-10-14 17:56:16 -04:00