Impact
The C‑MOR Video Surveillance web interface contains a path‑traversal flaw in the 'cam' parameter of the show‑movies.pml endpoint. By supplying crafted traversal sequences, an attacker may cause the application to read arbitrary files from the server filesystem, potentially exposing sensitive configuration, credentials, or other confidential data. This vulnerability is categorized as CWE‑22 and can lead to confidentiality compromise or serve as a foothold for further attacks.
Affected Systems
Affected software includes the C‑MOR Video Surveillance web interface up to version 6.0104. No other vendors or versions were explicitly identified, and the vulnerability description references only the 'cam' parameter of show‑movies.pml. Users running any variant of the C‑MOR platform before the 6.0104 release should verify the version in use.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of 2% suggests that exploitation is possible but not widespread at this time. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the flaw does not require authentication and is triggered through the public web interface. The likely attack vector is remote over HTTP/HTTPS. An attacker can send crafted URLs containing traversal sequences such as '../../' to the 'cam' parameter and potentially retrieve any file the underlying process can read.
OpenCVE Enrichment