CVE-2018-14910: CSRF
Published Aug 3, 2018
·Updated
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/adminip.php (aka /adm1n/adminip.php). The code is executed by visiting adm1n/adminip.php or data/admin/ip.php. This can also be exploited through CSRF.
Affected Software
1 affected component
SEACMS SEACMS=6.61
Event History
Aug 3, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-14910.
2
What is the severity of CVE-2018-14910?
The severity of CVE-2018-14910 is high.
3
Which software version is affected?
SeaCMS v6.61 is affected by this vulnerability.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by placing PHP code in an allowed IP address to /admin/admin_ip.php or data/admin/ip.php and then visiting those URLs.
5
Is there a fix available for CVE-2018-14910?
The fix for CVE-2018-14910 is not specified in the provided information. It is recommended to check the official vendor's website or contact them for a patch or workaround.