CVE-2021-39426: Code Injection
An issue was discovered in /Upload/admin/adminnotify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39426?
CVE-2021-39426 is a vulnerability in Seacms 11.4 that allows attackers to execute arbitrary PHP code via a malicious parameter.
How severe is CVE-2021-39426?
CVE-2021-39426 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2021-39426?
An attacker can exploit CVE-2021-39426 by sending a specially crafted request to the /Upload/admin/admin_notify.php endpoint in Seacms 11.4.
What is the affected software version of CVE-2021-39426?
CVE-2021-39426 affects Seacms version 11.4.
Is there a fix available for CVE-2021-39426?
At the moment, there is no official fix available for CVE-2021-39426. It is recommended to apply any patches or updates provided by the vendor or seek alternative measures to mitigate the vulnerability.