(#Several vulnerabilities have been identified in ZoneMinder:#- CVE-2017-5367: several cross-site scripting. A remote attacker could exploit them in order to execute arbitrary JavaScript or HTML code by enticing their victim into following a specially formed link##- CVE-2017-5368: cross-site request forgery. A remote attacker could perform certain operations with the privileges of their victim by enticing them into opening a malicious link.##Proofs of concept are available.##The zoneminder packages provided by Debian Wheezy 7 are vulnerable.)