C-MOR Video Surveillance Faces Major Security Flaw: High-Risk Path Traversal Vulnerability Exposed

C-MOR Video Surveillance users, beware! A relative path traversal vulnerability (CWE-23) in version 5.2401 allows authenticated users to download arbitrary files. Update to version 6.00PL1 to avoid playing peek-a-boo with your system files.

Hot Take:

Who needs a hacker thriller movie when you’ve got C-MOR? This surveillance system is so transparent, you might just see through to the other side—literally.

Key Points:

  • C-MOR Video Surveillance had a high-risk relative path traversal vulnerability.
  • The vulnerability allowed authenticated users to download arbitrary files from the system.
  • Two scripts, “download-bkf.pml” and “show-movies.pml,” were identified as vulnerable.
  • The issue was fixed in version 6.00PL1 of the software.
  • The vulnerability was responsibly disclosed and patched over several months.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here