logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-40520

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-40520

Description:
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
Last updated date:
08/01/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/12/2024
Reference url to background

https://gitee.com/fushuling/cve/blob/master/SeaCMS%2012.9%20admin_config_mark.php%20code%20injection.md

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy