CVE-2024-39027: SQL Injection
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39027?
CVE-2024-39027 is categorized as a high severity vulnerability due to the potential for unauthorized access to sensitive database information.
How do I fix CVE-2024-39027?
To fix CVE-2024-39027, update to a patched version of SeaCMS that addresses the SQL injection vulnerability in version 12.9.
What type of vulnerability is CVE-2024-39027?
CVE-2024-39027 is an unauthorized SQL injection vulnerability affecting SeaCMS v12.9.
Which versions of SeaCMS are affected by CVE-2024-39027?
CVE-2024-39027 specifically affects SeaCMS version 12.9.
What impact does CVE-2024-39027 have on data security?
CVE-2024-39027 can lead to sensitive database information exposure due to SQL injection through the cid parameter.