First published: Sat Nov 17 2018(Updated: )
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19349 is a vulnerability in SeaCMS v6.64 that allows for SQL injection via the admin_makehtml.php topic parameter.
CVE-2018-19349 affects Seacms v6.64 by allowing attackers to perform SQL injection through the topic parameter of admin_makehtml.php.
CVE-2018-19349 has a severity rating of 7.2 (high).
To fix CVE-2018-19349, update SeaCMS to a version that does not have the SQL injection vulnerability and ensure proper handling of user input.
You can find more information about CVE-2018-19349 at the following link: https://github.com/Xmansec/seacms_vul/blob/master/SQL/README.md