Files
zoneminder/web/ajax/stats.php
T
Isaac Connor da04fd65aa fix: require auth for every ajax request regardless of view refs GHSA-vvw3-j4p4-4rgx
The ZM_OPT_USE_AUTH gate in index.php exempted view=login and view=none
so those pages can render without a session. The same condition also
guarded the ajax dispatcher, so view=none&request=<name> (or
view=login&request=<name>) reached web/ajax/<name>.php with no user.
ajax/stats.php's raw branch has no permission check of its own and
returned Events rows (Name, Cause, Notes, DiskSpace) joined with the
monitor name to anonymous clients.

Apply the login/none exemption only when there is no request, so any
request= without a user gets the 401. No ajax handler is meant to be
reached unauthenticated: login and logout are POST actions on views,
skin.js skips its polling on the login and none views, and the auth
revalidation probe already uses view=request and expects a 401/403 for
a dead session.

Also check canView('Events') at the top of ajax/stats.php, matching
getStatsTableHTML() used by its non-raw branch, so the raw branch no
longer depends on the gate alone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 6699ae212ea8c5d7b9ee29f38c05c0135635fe8f)
2026-09-24 19:46:37 -04:00

41 lines
1.9 KiB
PHP

<?php
if (!canView('Events')) ajaxError('Insufficient permissions');
if (empty($_REQUEST['eid'])) ajaxError('Event Id Not Provided');
if (empty($_REQUEST['fid'])) ajaxError('Frame Id Not Provided');
$eid = $_REQUEST['eid'];
$fid = $_REQUEST['fid'];
$row = ( isset($_REQUEST['row']) ) ? $_REQUEST['row'] : '';
$raw = isset($_REQUEST['raw']);
$data = array();
if ($raw) {
$data['raw'] = array();
$sql = 'SELECT S.*,E.*,Z.Name AS ZoneName,Z.Units,Z.Area,M.Name AS MonitorName
FROM Stats AS S LEFT JOIN Events AS E ON S.EventId = E.Id LEFT JOIN Zones AS Z ON S.ZoneId = Z.Id LEFT JOIN Monitors AS M ON E.MonitorId = M.Id
WHERE S.EventId = ? AND S.FrameId = ? ORDER BY S.ZoneId';
$stats = dbFetchAll($sql, NULL, array($eid, $fid));
foreach ($stats as $stat) {
$stat['ZoneName'] = validHtmlStr($stat['ZoneName']);
$stat['PixelDiff'] = validHtmlStr($stat['PixelDiff']);
$stat['AlarmPixels'] = sprintf('%d (%.1f%%)', $stat['AlarmPixels'], (100*$stat['AlarmPixels']/$stat['Area']));
$stat['FilterPixels'] = sprintf('%d (%.1f%%)', $stat['FilterPixels'], (100*$stat['FilterPixels']/$stat['Area']));
$stat['BlobPixels'] = sprintf('%d (%.1f%%)', $stat['BlobPixels'], (100*$stat['BlobPixels']/$stat['Area']));
$stat['Blobs'] = validHtmlStr($stat['Blobs']);
if ($stat['Blobs'] > 1) {
$stat['BlobSizes'] = sprintf('%d-%d (%.1f%%-%.1f%%)', $stat['MinBlobSize'], $stat['MaxBlobSize'], (100*$stat['MinBlobSize']/$stat['Area']), (100*$stat['MaxBlobSize']/$stat['Area']));
} else {
$stat['BlobSizes'] = sprintf('%d (%.1f%%)', $stat['MinBlobSize'], 100*$stat['MinBlobSize']/$stat['Area']);
}
$stat['AlarmLimits'] = validHtmlStr($stat['MinX'].','.$stat['MinY'].'-'.$stat['MaxX'].','.$stat['MaxY']);
$data['raw'][] = $stat;
} # end foreach stat/zone
} else {
$data['html'] = getStatsTableHTML($eid, $fid, $row);
$data['id'] = '#contentStatsTable' .$row;
}
ajaxResponse($data);
return;
?>