Impact
The vulnerability is an unsanitized cross‑site scripting flaw in the size parameter of the ptzpreset.pml and showmovies.pml components. An attacker can inject malicious script that, when executed in the victim’s browser, allows arbitrary code execution within the context of the web application. This flaw directly compromises confidentiality, integrity, and availability of the surveillance system, potentially giving attackers control over the monitored environment.
Affected Systems
The flaw affects za‑internet GmbH C-MOR Video Surveillance software versions up to and including V6.0104. Users running any of these releases are vulnerable unless the size parameter has been restricted or the application updated.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is below 1%, suggesting low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely by any user capable of supplying the size parameter, likely through the web interface, as the description states a remote attacker can execute code. No additional access or privilege escalation is required beyond interaction with the exposed component.
OpenCVE Enrichment