Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $REQUEST['PHPSELF'], without applying any proper filtration.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-7325.json"