CVE-2024-39028: Command Injection
Published Jul 5, 2024
·Updated
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via adminping.php.
Affected Software
1 affected component
SEACMS SEACMS<=12.9
Event History
Jul 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39028?
CVE-2024-39028 has a critical severity as it allows remote code execution in SeaCMS versions up to 12.9.
2
How do I fix CVE-2024-39028?
To fix CVE-2024-39028, users should upgrade SeaCMS to a version later than 12.9 that addresses this vulnerability.
3
Who is affected by CVE-2024-39028?
CVE-2024-39028 affects all users of SeaCMS versions 12.9 and below.
4
What kind of attacks can exploit CVE-2024-39028?
CVE-2024-39028 can be exploited by remote attackers to execute arbitrary code on the server.
5
Is there a workaround for CVE-2024-39028?
There are no known effective workarounds for CVE-2024-39028, so upgrading is strongly recommended.