Description
The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.
Published: 2026-09-15
Score: 7.5 High
EPSS: 1.7% Low
KEV: No
Impact: Remote Path Traversal
Action: Apply Patch
AI Analysis

Impact

The C‑MOR Video Surveillance web interface contains a path‑traversal flaw in the 'cam' parameter of the show‑movies.pml endpoint. By supplying crafted traversal sequences, an attacker may cause the application to read arbitrary files from the server filesystem, potentially exposing sensitive configuration, credentials, or other confidential data. This vulnerability is categorized as CWE‑22 and can lead to confidentiality compromise or serve as a foothold for further attacks.

Affected Systems

Affected software includes the C‑MOR Video Surveillance web interface up to version 6.0104. No other vendors or versions were explicitly identified, and the vulnerability description references only the 'cam' parameter of show‑movies.pml. Users running any variant of the C‑MOR platform before the 6.0104 release should verify the version in use.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score of 2% suggests that exploitation is possible but not widespread at this time. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the flaw does not require authentication and is triggered through the public web interface. The likely attack vector is remote over HTTP/HTTPS. An attacker can send crafted URLs containing traversal sequences such as '../../' to the 'cam' parameter and potentially retrieve any file the underlying process can read.

Generated by OpenCVE AI on September 20, 2026 at 18:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade C‑MOR Video Surveillance to a version that resolves the path traversal flaw, such as version 6.0105 or later if available.
  • If an upgrade is not immediately possible, restrict or disable external access to the show‑movies.pml endpoint through the web server or reverse proxy.
  • Implement input validation and directory canonicalization on the 'cam' parameter to reject traversal patterns, as recommended for CWE‑22 mitigation.
  • Monitor logs for abnormal file access patterns and apply security controls to limit the file system permissions of the web application.

Generated by OpenCVE AI on September 20, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in C‑MOR Video Surveillance show‑movies Endpoint

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in C‑MOR Video Surveillance show‑movies Endpoint

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T17:43:46.546Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51134

cve-icon Vulnrichment

Updated: 2026-09-16T17:43:06.151Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:17:17.493

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-51134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')