Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42gg-98x6-j389

Опубликовано: 20 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

EPSS

Процентиль: 35%
0.00144
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.7
nvd
больше 1 года назад

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

EPSS

Процентиль: 35%
0.00144
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-94