CVE-2024-50808

HIGH

SeaCms 13.1 - Code Injection via Notify Variable in Admin Notify Module

Title source: llm
STIX 2.1

Description

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0061
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
seacms/seacms 13.1
Published Nov 08, 2024
Tracked Since Feb 18, 2026