PT-2024-31307 · Seacms · Seacms
Nn0Nkey
·
Published
2024-09-03
·
Updated
2024-09-07
·
CVE-2024-44921
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SeaCMS version 12.9
Description
A SQL injection vulnerability was discovered in SeaCMS via the
id parameter at the "/dmplayer/dmku/index.php?ac=del" endpoint. This issue allows for potential SQL injection attacks.Recommendations
For SeaCMS version 12.9, consider disabling the
id parameter in the "/dmplayer/dmku/index.php?ac=del" endpoint as a temporary workaround until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the id parameter in this endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seacms