An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory "/srv/www/backups" on the C-MOR system, and can thus be accessed via the URL https://<HOST>/backup/upload_<FILENAME>. Due to broken access control, low-privileged authenticated users can also use this file upload functionality.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 04 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared C-mor
C-mor c-mor Video Surveillance
CPEs cpe:2.3:a:c-mor:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*
Vendors & Products C-mor
C-mor c-mor Video Surveillance

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Fri, 06 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Za-internet
Za-internet c-mor Video Surveillance
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*
Vendors & Products Za-internet
Za-internet c-mor Video Surveillance
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 07:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*
Vendors & Products Za-internet
Za-internet c-mor Video Surveillance
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Za-internet
Za-internet c-mor Video Surveillance
Weaknesses CWE-434
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*
Vendors & Products Za-internet
Za-internet c-mor Video Surveillance
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory "/srv/www/backups" on the C-MOR system, and can thus be accessed via the URL https://<HOST>/backup/upload_<FILENAME>. Due to broken access control, low-privileged authenticated users can also use this file upload functionality.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-06T06:03:35.338Z

Reserved: 2024-08-22T00:00:00

Link: CVE-2024-45171

cve-icon Vulnrichment

Updated: 2024-09-05T15:55:22.425Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T16:15:08.477

Modified: 2025-09-04T16:35:58.323

Link: CVE-2024-45171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.