First published: Thu Jul 19 2018(Updated: )
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for SeaCMS v6.61 is CVE-2018-14421.
The severity of CVE-2018-14421 is high with a severity value of 8.8.
CVE-2018-14421 allows remote code execution by placing PHP code in a movie picture address to /admin/admin_video.php and executing it by visiting /details/index.php.
CVE-2018-14421 can be exploited by using CSRF and placing PHP code in a movie picture address to gain remote code execution.
At the moment, there is no specific fix available for CVE-2018-14421. It is recommended to update to a patched version or implement strong access controls to mitigate the vulnerability.