Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45170

Опубликовано: 04 сент. 2024
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative users. However, access those functions is restricted via the web application user interface and not checked on the server side. Thus, by sending corresponding HTTP requests to the web server of the C-MOR web interface, low privileged users can also use administrative functionality, for instance downloading backup files or changing configuration settings.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:c-mor:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.0056
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
github
больше 1 года назад

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative users. However, access those functions is restricted via the web application user interface and not checked on the server side. Thus, by sending corresponding HTTP requests to the web server of the C-MOR web interface, low privileged users can also use administrative functionality, for instance downloading backup files or changing configuration settings.

EPSS

Процентиль: 68%
0.0056
Низкий

8.1 High

CVSS3

Дефекты

CWE-284