CVE-2024-40518: Input Validation
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by adminweixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40518?
CVE-2024-40518 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-40518?
To fix CVE-2024-40518, you should apply any available patches from SeaCMS or sanitize user input in the affected script.
Who is affected by CVE-2024-40518?
CVE-2024-40518 affects all installations of SeaCMS version 12.9.
What impact does CVE-2024-40518 have?
CVE-2024-40518 allows authenticated attackers to execute arbitrary commands on the server, potentially leading to a full system compromise.
Is CVE-2024-40518 being actively exploited?
Yes, CVE-2024-40518 is actively exploited in the wild, making it crucial to remediate the vulnerability immediately.