{"id":"CVE-2026-51133","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-51133","generatedAt":"2026-09-20T14:59:59.043Z","title":"Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component","description":"Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component","published":"2026-09-15T20:17:17.000Z","lastModified":"2026-09-17T16:17:29.000Z","status":"Received","sourceIdentifier":"cve@mitre.org","cvss":{"version":"3.1","score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"cwe":["CWE-79"],"affected":[],"epss":{"score":0.00866,"percentile":0.57115,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":1,"verified":false,"firstPublished":"2026-08-31","source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[{"edbId":52665,"kind":"exploit","title":"C-MOR  6.0104 - Cross-Site Scripting (XSS)","url":"https://www.exploit-db.com/exploits/52665","sourceUrl":"https://gitlab.com/exploit-database/exploitdb/-/blob/main/exploits/hardware/webapps/52665.txt","file":"exploits/hardware/webapps/52665.txt","published":"2026-08-31","added":"2026-08-31","updated":"2026-08-31","author":"Samir Shamdin","type":"webapps","platform":"hardware","port":null,"verified":false,"codes":["CVE-2026-51133"],"tags":null,"aliases":null,"applicationUrl":null,"screenshotUrl":null,"referenceUrl":null}]},"verdict":{"level":"high","text":"A public exploit is published in Exploit-DB, so the technical barrier is gone even though the severity is medium and EPSS is 0.9%. Treat it as high on anything reachable from the internet."},"changes":[{"kind":"exploit","label":"Public exploit","at":"2026-08-31T00:00:00.000Z","detail":{"type":"webapps","edbId":52665,"title":"C-MOR  6.0104 - Cross-Site Scripting (XSS)","platform":"hardware","verified":false,"publishedAt":"2026-08-31"},"summary":"Public exploit published in Exploit-DB: C-MOR  6.0104 - Cross-Site Scripting (XSS) (webapps, hardware)."}],"references":[{"url":"https://albcyberguards.com/blog/cve-2026-51133-c-mor-cross-site-scripting","source":"cve@mitre.org"},{"url":"https://www.c-mor.com/video-surveillance-info/video-surveillance-change-log","source":"cve@mitre.org"},{"url":"https://albcyberguards.com/blog/cve-2026-51133-c-mor-cross-site-scripting","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-51133","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}