We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-45174



Assignermitre
Reserved2024-08-22
Published2024-09-04
Updated2024-09-06

Description

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.

References

https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-023.txt

https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030

cve.org CVE-2024-45174

nvd.nist.gov CVE-2024-45174

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-45174
Subscribe to our newsletter to learn more about our work.