CVE-2018-19349: SQL Injection
Published Nov 17, 2018
·Updated
In SeaCMS v6.64, there is SQL injection via the adminmakehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
Affected Software
1 affected component
SEACMS SEACMS=6.64
Event History
Nov 17, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19349?
CVE-2018-19349 is a vulnerability in SeaCMS v6.64 that allows for SQL injection via the admin_makehtml.php topic parameter.
2
How does CVE-2018-19349 affect Seacms v6.64?
CVE-2018-19349 affects Seacms v6.64 by allowing attackers to perform SQL injection through the topic parameter of admin_makehtml.php.
3
What is the severity of CVE-2018-19349?
CVE-2018-19349 has a severity rating of 7.2 (high).
4
How can I fix CVE-2018-19349?
To fix CVE-2018-19349, update SeaCMS to a version that does not have the SQL injection vulnerability and ensure proper handling of user input.
5
Where can I find more information about CVE-2018-19349?
You can find more information about CVE-2018-19349 at the following link: https://github.com/Xmansec/seacms_vul/blob/master/SQL/README.md