PT-2024-31307 · Seacms · Seacms

Nn0Nkey

·

Published

2024-09-03

·

Updated

2024-09-07

·

CVE-2024-44921

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeaCMS version 12.9
Description A SQL injection vulnerability was discovered in SeaCMS via the id parameter at the "/dmplayer/dmku/index.php?ac=del" endpoint. This issue allows for potential SQL injection attacks.
Recommendations For SeaCMS version 12.9, consider disabling the id parameter in the "/dmplayer/dmku/index.php?ac=del" endpoint as a temporary workaround until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the id parameter in this endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-44921

Affected Products

Seacms