PT-2024-31458 · Za Internet · Za-Internet C-Mor Video Surveillance

Chris Beiter

+2

·

Published

2024-09-04

·

Updated

2024-09-05

·

CVE-2024-45174

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions za-internet C-MOR Video Surveillance versions 5.2401 through 6.00PL01
Description An issue was discovered due to improper validation of user-supplied data, making different functionalities of the C-MOR web interface vulnerable to SQL injection attacks. This allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.
Recommendations For versions 5.2401 through 6.00PL01, as a temporary workaround, consider restricting access to the C-MOR web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-45174

Affected Products

Za-Internet C-Mor Video Surveillance