Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-42598


SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.


Published

2024-08-20T16:15:11.727

Last Modified

2025-03-28T16:53:29.593

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application seacms seacms 13.0 Yes

References