First published: Fri Sep 20 2024(Updated: )
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | ||
Tina Tinacms | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46640 is classified as a critical remote code execution vulnerability.
To fix CVE-2024-46640, update to the latest version of SeaCMS where the vulnerability has been addressed.
CVE-2024-46640 affects SeaCMS version 13.2.
CVE-2024-46640 is caused by a lack of execution of the check function during file operations in sql.class.chp.
Yes, CVE-2024-46640 can be exploited remotely through MySQL slow query methods.