Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-46640


SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.


Published

2024-09-20T21:15:12.700

Last Modified

2025-03-28T17:12:25.097

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application seacms seacms 13.2 Yes

References