CVE-2024-45178
C-MOR Video Surveillance 5.2401 Path Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR system. Another path traversal attack is in the script show-movies.pml, which can be exploited via the parameter cam.
C-MOR Video Surveillance version 5.2401 suffers from a path traversal vulnerability.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-08-22 CVE Reserved
- 2024-09-05 CVE Published
- 2024-09-06 CVE Updated
- 2024-09-06 EPSS Updated
- 2024-09-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/181380 | 2024-09-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Za-internet Search vendor "Za-internet" | C-mor Video Surveillance Search vendor "Za-internet" for product "C-mor Video Surveillance" | * | - |
Affected
|