CVE-2018-16445: SQL Injection
Published Sep 4, 2018
·Updated
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admintopicvod.php request.
Affected Software
1 affected component
SEACMS SEACMS<=6.61
Event History
Sep 4, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16445.
2
What is the severity level of CVE-2018-16445?
CVE-2018-16445 has a severity level of critical.
3
How does the SQL injection occur in CVE-2018-16445?
SQL injection occurs via the tid parameter in an adm1n/admin_topic_vod.php request in CVE-2018-16445.
4
What is the affected software version for CVE-2018-16445?
The affected software version for CVE-2018-16445 is SeaCMS up to and including version 6.61.
5
Is there a fix available for CVE-2018-16445?
Yes, a fix is available for CVE-2018-16445. It is recommended to update to a version of SeaCMS that is not affected by the vulnerability.