Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-42599

Опубликовано: 22 авг. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:seacms:seacms:13.0:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00396
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
больше 1 года назад

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

EPSS

Процентиль: 60%
0.00396
Низкий

8.8 High

CVSS3

Дефекты

CWE-94