PT-2024-23493 · Seacms · Seacms

Published

2024-04-04

·

Updated

2024-08-28

·

CVE-2024-30565

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeaCMS version 12.9
Description An issue was discovered that allows remote attackers to execute arbitrary code via the admin notify.php endpoint.
Recommendations For SeaCMS version 12.9, consider disabling access to the admin notify.php endpoint until a patch is available.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-30565

Affected Products

Seacms