PT-2024-23725 · Semcms · Semcms

Jixin Zhang

+1

·

Published

2024-04-02

·

Updated

2024-07-03

·

CVE-2024-31012

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEMCMS version 4.8
Description An issue in SEMCMS allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
Recommendations For SEMCMS version 4.8, consider disabling access to the upload.php file as a temporary workaround until a patch is available. Restrict access to sensitive information and privileges to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-31012

Affected Products

Semcms