CVE-2024-40518
HIGHSeaCMS 12.9 - Authenticated Remote Code Execution via admin_weixin.php
Title source: llmDescription
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
References (1)
Core 1
Scores
CVSS v3
8.8
EPSS
0.0158
EPSS Percentile
81.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (1)
seacms/seacms
12.9
Published
Jul 12, 2024
Tracked Since
Feb 18, 2026