An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks.

Subscriptions

Vendors Products
C-mor Video Surveillance Subscribe
Za-internet Subscribe
C-mor Video Surveillance Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared C-mor
C-mor c-mor Video Surveillance
CPEs cpe:2.3:a:c-mor:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*
cpe:2.3:a:c-mor:c-mor_video_surveillance:6.00:patch_level_01:*:*:*:*:*:*
Vendors & Products C-mor
C-mor c-mor Video Surveillance

Fri, 06 Sep 2024 07:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:*:*:*:*:*:*:*:*
Vendors & Products Za-internet
Za-internet c-mor Video Surveillance
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Za-internet
Za-internet c-mor Video Surveillance
Weaknesses CWE-352
CPEs cpe:2.3:a:za-internet:c-mor_video_surveillance:*:*:*:*:*:*:*:*
Vendors & Products Za-internet
Za-internet c-mor Video Surveillance
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-06T06:03:36.295Z

Reserved: 2024-08-22T00:00:00.000Z

Link: CVE-2024-45172

cve-icon Vulnrichment

Updated: 2024-09-06T06:03:36.295Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-04T20:15:09.167

Modified: 2025-09-04T16:29:17.197

Link: CVE-2024-45172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:01:06Z

Weaknesses