First published: Fri Mar 22 2024(Updated: )
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | ||
Tina Tinacms | =12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29275 is classified as a critical vulnerability due to its potential for remote code execution and unauthorized access to sensitive information.
To fix CVE-2024-29275, update SeaCMS to the latest version that addresses this SQL injection vulnerability.
The potential impacts of CVE-2024-29275 include unauthorized data access, arbitrary code execution, and compromise of sensitive information.
CVE-2024-29275 affects users of SeaCMS version 12.9 who have not implemented any security measures to mitigate SQL injection vulnerabilities.
Yes, CVE-2024-29275 can be exploited by remote unauthenticated attackers through the id parameter in class.php.