CVE-2024-4595: SEMCMS function.php locate sql injection
Published May 7, 2024
·Updated
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263317 was assigned to this vulnerability.
Affected Software
2 affected components
SEMCMS SEMCMS<=4.8
Sem-cms Semcms<=4.8
Event History
May 7, 2024
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4595?
CVE-2024-4595 is classified as a critical vulnerability.
2
How do I fix CVE-2024-4595?
To fix CVE-2024-4595, upgrade SEMCMS to a version later than 4.8.
3
What type of vulnerability is CVE-2024-4595?
CVE-2024-4595 is an SQL injection vulnerability.
4
Can CVE-2024-4595 be exploited remotely?
Yes, CVE-2024-4595 can be exploited remotely.
5
Which versions of SEMCMS are affected by CVE-2024-4595?
SEMCMS versions up to and including 4.8 are affected by CVE-2024-4595.