PoC Index

CVE-2024-45174

HIGH 8.1EPSS 1.3%

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
1.31% chance of exploitation in the next 30 days, 69th percentile
Published
2024-09-04
Updated
2024-09-06

Proof-of-concept exploits (1)

References

Related