Files
zoneminder/web/ajax
Isaac Connor da04fd65aa fix: require auth for every ajax request regardless of view refs GHSA-vvw3-j4p4-4rgx
The ZM_OPT_USE_AUTH gate in index.php exempted view=login and view=none
so those pages can render without a session. The same condition also
guarded the ajax dispatcher, so view=none&request=<name> (or
view=login&request=<name>) reached web/ajax/<name>.php with no user.
ajax/stats.php's raw branch has no permission check of its own and
returned Events rows (Name, Cause, Notes, DiskSpace) joined with the
monitor name to anonymous clients.

Apply the login/none exemption only when there is no request, so any
request= without a user gets the 401. No ajax handler is meant to be
reached unauthenticated: login and logout are POST actions on views,
skin.js skips its polling on the login and none views, and the auth
revalidation probe already uses view=request and expects a 401/403 for
a dead session.

Also check canView('Events') at the top of ajax/stats.php, matching
getStatsTableHTML() used by its non-raw branch, so the raw branch no
longer depends on the gate alone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 6699ae212ea8c5d7b9ee29f38c05c0135635fe8f)
2026-09-24 19:46:37 -04:00
..
2019-02-22 09:19:07 -05:00
2023-04-23 13:15:11 -04:00
2018-12-29 09:52:58 -05:00