First published: Fri Jul 05 2024(Updated: )
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39027 is categorized as a high severity vulnerability due to the potential for unauthorized access to sensitive database information.
To fix CVE-2024-39027, update to a patched version of SeaCMS that addresses the SQL injection vulnerability in version 12.9.
CVE-2024-39027 is an unauthorized SQL injection vulnerability affecting SeaCMS v12.9.
CVE-2024-39027 specifically affects SeaCMS version 12.9.
CVE-2024-39027 can lead to sensitive database information exposure due to SQL injection through the cid parameter.