SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitee.com/zheng_botong/CVE-2024-46640 |
|
History
Fri, 28 Mar 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:seacms:seacms:13.2:*:*:*:*:*:*:* |
Mon, 23 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Seacms
Seacms seacms |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Seacms
Seacms seacms |
|
| Metrics |
cvssV3_1
|
Fri, 20 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-20T00:00:00
Updated: 2024-09-23T15:30:29.306Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46640
Updated: 2024-09-23T15:30:23.454Z
Status : Analyzed
Published: 2024-09-20T21:15:12.700
Modified: 2025-03-28T17:12:25.097
Link: CVE-2024-46640
No data.