CVE-2024-30565

HIGH

Seacms - Code Injection

Title source: rule
STIX 2.1

Description

An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

Scores

CVSS v3 8.8
EPSS 0.0257
EPSS Percentile 85.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
seacms/seacms 12.9
Published Apr 04, 2024
Tracked Since Feb 18, 2026