Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-40519

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
Attacker Value
Unknown

CVE-2024-40518

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
Attacker Value
Unknown

CVE-2024-39027

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.
Attacker Value
Unknown

CVE-2024-31611

Disclosure Date: June 10, 2024 (last updated June 13, 2024)
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
Attacker Value
Unknown

CVE-2023-46987

Disclosure Date: December 28, 2023 (last updated February 25, 2025)
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
Attacker Value
Unknown

CVE-2023-44172

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
Attacker Value
Unknown

CVE-2023-44171

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
Attacker Value
Unknown

CVE-2023-44170

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
Attacker Value
Unknown

CVE-2023-44169

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
Attacker Value
Unknown

CVE-2023-43216

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.