Description
Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Patch
AI Analysis

Impact

The vulnerability is an unsanitized cross‑site scripting flaw in the size parameter of the ptzpreset.pml and showmovies.pml components. An attacker can inject malicious script that, when executed in the victim’s browser, allows arbitrary code execution within the context of the web application. This flaw directly compromises confidentiality, integrity, and availability of the surveillance system, potentially giving attackers control over the monitored environment.

Affected Systems

The flaw affects za‑internet GmbH C-MOR Video Surveillance software versions up to and including V6.0104. Users running any of these releases are vulnerable unless the size parameter has been restricted or the application updated.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score is below 1%, suggesting low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely by any user capable of supplying the size parameter, likely through the web interface, as the description states a remote attacker can execute code. No additional access or privilege escalation is required beyond interaction with the exposed component.

Generated by OpenCVE AI on September 17, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a version newer than V6.0104 to remove the vulnerable code paths.
  • If an update is unavailable, block or sanitize traffic to the size parameter by configuring the web server or firewall rules to reject requests containing unsafe input.
  • Implement input validation for all parameters used in ptzpreset.pml and showmovies.pml to prevent script injection.

Generated by OpenCVE AI on September 17, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in C‑MOR Video Surveillance

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-17T15:27:54.637Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51133

cve-icon Vulnrichment

Updated: 2026-09-17T15:27:38.924Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:17:17.350

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-51133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')