CVE-2026-51133
Deferred Deferred - Pending Action

Cross Site Scripting in C-MOR Video Surveillance

Vulnerability report for CVE-2026-51133, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-22

Assigner: MITRE

Description

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-22
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
za-internet_gmbh c-mor_video_surveillance to 6.0104 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross Site Scripting (XSS) vulnerability in the C-MOR Video Surveillance software by za-internet GmbH. It affects versions up to and including V6.0104. The flaw allows a remote attacker to inject and execute arbitrary malicious scripts via the 'size' parameter in the 'ptzpreset.pml' and 'showmovies.pml' components.

Detection Guidance

Check if your C-MOR Video Surveillance system is running a version <= V6.0104. Inspect network traffic for requests to ptzpreset.pml or showmovies.pml with suspicious parameters like size. Use tools like curl to test endpoints: curl -v 'http://<target>/ptzpreset.pml?size=<script>alert(1)</script>'

Monitor web server logs for unusual input in size parameter. Ensure input validation is bypassed by sending encoded or malformed payloads.

Impact Analysis

An attacker could exploit this to run malicious code in a user's browser when they access the vulnerable C-MOR Video Surveillance system. This could lead to theft of session cookies, account takeover, or unauthorized actions on behalf of the user.

Compliance Impact

This vulnerability, a Cross Site Scripting flaw in C-MOR Video Surveillance software, could potentially allow unauthorized code execution. Such vulnerabilities may lead to unauthorized access to sensitive video surveillance data, which could violate GDPR requirements for data protection and privacy if personal data is exposed. For HIPAA, if the system is used in healthcare settings, unauthorized access could compromise protected health information.

Mitigation Strategies

Upgrade C-MOR Video Surveillance to the latest version beyond V6.0104 immediately. If upgrading is not possible, restrict access to the vulnerable components via firewall rules or disable remote access.

Apply input validation to sanitize the size parameter in ptzpreset.pml and showmovies.pml. Monitor for any signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51133. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart