An issue was discovered in za-internet C-MOR Video Surveillance 5.2401
Published Sep 5, 2024
7.1
HIGHCVSS 3.1
EPSS 1.27%
Description
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR system. Another path traversal attack is in the script show-movies.pml, which can be exploited via the parameter cam.
Affected products
No data.
- 5.2401
-
Affected
- 5.2401
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| ZA-Internet | C-Mor Video Surveillance | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- http://seclists.org/fulldisclosure/2024/Sep/18 ExploitMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41356 Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-025.txt ExploitVendor Advisory
- https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2024/Sep/18 | ExploitMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41356 | Advisory | |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-025.txt | ExploitVendor Advisory | |
| https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data