PT-2022-10913 · Seacms · Seacms

Tr0Uble-Maker

·

Published

2022-12-15

·

Updated

2022-12-21

·

CVE-2021-39426

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Seacms version 11.4
Description An issue was discovered in the /Upload/admin/admin notify.php file, allowing attackers to execute arbitrary PHP code via the notify1 parameter when the action parameter equals 'set'.
Recommendations For Seacms version 11.4, consider restricting access to the /Upload/admin/admin notify.php file or disabling the notify1 parameter when the action parameter equals 'set' until a patch is available. Avoid using the notify1 parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39426

Affected Products

Seacms