PT-2024-31460 · Za Internet · Za-Internet C-Mor Video Surveillance
Chris Beiter
+2
·
Published
2024-09-05
·
Updated
2025-03-17
·
CVE-2024-45176
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
za-internet C-MOR Video Surveillance version 5.2401
Description
An issue was discovered due to improper input validation, making the C-MOR web interface vulnerable to reflected cross-site scripting (XSS) attacks. Different functions are prone to reflected cross-site scripting attacks due to insufficient user input validation.
Recommendations
For version 5.2401, consider disabling the web interface temporarily until a patch is available to prevent exploitation of the reflected cross-site scripting vulnerability. Restrict access to the C-MOR web interface to minimize the risk of exploitation. Avoid using the web interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Za-Internet C-Mor Video Surveillance