turabiaslan

1 exploit Active since Mar 2024
CVE-2024-28405 WRITEUP HIGH WRITEUP
SEMCMS 4.8 - Unauthenticated Incorrect Access Control via Early SEMCMS_Funtion.php Installation
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
CVSS 7.2