SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
History

Mon, 23 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Seacms
Seacms seacms
Weaknesses CWE-94
CPEs cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*
Vendors & Products Seacms
Seacms seacms
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 21:00:00 +0000

Type Values Removed Values Added
Description SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-20T00:00:00

Updated: 2024-09-23T15:30:29.306Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46640

cve-icon Vulnrichment

Updated: 2024-09-23T15:30:23.454Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-20T21:15:12.700

Modified: 2024-09-26T13:32:55.343

Link: CVE-2024-46640

cve-icon Redhat

No data.