CVE-2018-19349

HIGH

SeaCMS v6.64 - SQL Injection via admin_makehtml.php topic parameter

Title source: llm
STIX 2.1

Description

In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0100
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
seacms/seacms 6.64
Published Nov 17, 2018
Tracked Since Feb 18, 2026