mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
index.php skips csrf_check() for view=image because images are loaded through <img src>, and csrf_check() only validates POSTs in any case. The proxy= handler makes the server fetch a caller-supplied URL, so a page on another site could embed an <img> pointing at it and have a logged-in monitor editor's browser drive server-side requests to the LAN. When ZM_ENABLE_CSRF_MAGIC is on, the proxy branch now checks __csrf_magic from the request with csrf_check_tokens() and answers 403 without it. Plain image views are unaffected. The only caller, the camera discovery thumbnail on add_monitors, appends csrfMagicName and csrfMagicToken to its <img> URL, and now URL-encodes the camera stream URL so a stream URL containing & or " no longer truncates the proxy parameter or breaks out of the src attribute. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 2958f89c5af63040483ac8a389d1fd7080b777a7)