CVE-2024-30565

HIGH

SeaCMS 12.9 - Remote Code Execution via admin notify.php

Title source: llm
STIX 2.1

Description

An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

Scores

CVSS v3 8.8
EPSS 0.0161
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
seacms/seacms 12.9
Published Apr 04, 2024
Tracked Since Feb 18, 2026