SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-29T00:00:00

Updated: 2024-08-02T00:56:57.672Z

Reserved: 2024-03-08T00:00:00

Link: CVE-2024-28405

cve-icon Vulnrichment

Updated: 2024-08-01T15:54:25.027Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-29T15:15:11.123

Modified: 2024-08-01T16:35:07.140

Link: CVE-2024-28405

cve-icon Redhat

No data.