CVE-2024-46640
- EPSS 2.88%
- Veröffentlicht 20.09.2024 21:15:12
- Zuletzt bearbeitet 28.03.2025 17:12:25
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the ...
CVE-2024-44720
- EPSS 0.77%
- Veröffentlicht 09.09.2024 16:15:02
- Zuletzt bearbeitet 28.03.2025 17:12:30
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
CVE-2024-44721
- EPSS 0.35%
- Veröffentlicht 09.09.2024 16:15:02
- Zuletzt bearbeitet 28.03.2025 17:12:27
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
CVE-2024-44920
- EPSS 0.29%
- Veröffentlicht 03.09.2024 12:15:11
- Zuletzt bearbeitet 04.09.2024 14:59:58
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
CVE-2024-44921
- EPSS 0.58%
- Veröffentlicht 03.09.2024 12:15:11
- Zuletzt bearbeitet 04.09.2024 15:00:15
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
CVE-2024-44683
- EPSS 0.18%
- Veröffentlicht 30.08.2024 22:15:06
- Zuletzt bearbeitet 20.03.2025 21:15:21
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
CVE-2024-44918
- EPSS 0.15%
- Veröffentlicht 30.08.2024 17:15:15
- Zuletzt bearbeitet 28.03.2025 17:12:36
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-44916
- EPSS 1.27%
- Veröffentlicht 30.08.2024 16:15:09
- Zuletzt bearbeitet 28.03.2025 17:12:43
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
CVE-2024-44919
- EPSS 0.28%
- Veröffentlicht 29.08.2024 17:15:08
- Zuletzt bearbeitet 06.09.2024 22:54:56
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
CVE-2024-41444
- EPSS 0.13%
- Veröffentlicht 26.08.2024 17:15:06
- Zuletzt bearbeitet 05.09.2024 18:36:39
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.