CVE-2018-14421: CSRF
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/adminvideo.php (aka /backend/adminvideo.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for SeaCMS v6.61?
The vulnerability ID for SeaCMS v6.61 is CVE-2018-14421.
What is the severity of CVE-2018-14421?
The severity of CVE-2018-14421 is high with a severity value of 8.8.
How does CVE-2018-14421 allow remote code execution?
CVE-2018-14421 allows remote code execution by placing PHP code in a movie picture address to /admin/admin_video.php and executing it by visiting /details/index.php.
How can I exploit CVE-2018-14421?
CVE-2018-14421 can be exploited by using CSRF and placing PHP code in a movie picture address to gain remote code execution.
Is there a fix available for CVE-2018-14421?
At the moment, there is no specific fix available for CVE-2018-14421. It is recommended to update to a patched version or implement strong access controls to mitigate the vulnerability.