CVE-2024-42599
Seacms
CVE-2024-42599 is a remote code execution vulnerability in SeaCMS 13.0, allowing attackers to execute arbitrary commands. This vulnerability stems from inadequate restrictions in admin_files.php, enabling authenticated attackers to bypass file edit limitations and inject malicious code. Despite a CVSS score of 8.8, SOCRadar's Vulnerability Risk Score (SVRS) indicates a score of 30, suggesting a lower immediate threat level compared to other vulnerabilities. However, the potential for system compromise remains a significant risk. Successful exploitation could grant attackers full system privileges. Organizations using SeaCMS 13.0 should investigate this CVE and apply relevant patches or mitigations as needed to prevent unauthorized access and control of their systems. Even with a lower SVRS, the possibility of escalation and potential for severe impact necessitates proactive security measures. The ability to execute arbitrary commands makes this a critical issue requiring attention.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.