CVE-2024-40518
- Reference to the description:
- Description:
- SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
- Last updated date:
- 08/01/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 07/12/2024
- Reference url to background
https://gitee.com/fushuling/cve/blob/master/SeaCMS%2012.9%20admin_weixin.php%20code%20injection.md