CVE-2024-46640: Code Injection
Published Sep 20, 2024
·Updated
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
Affected Software
2 affected components
SEACMS SEACMS
SEACMS SEACMS=13.2
Event History
Sep 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46640?
CVE-2024-46640 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2024-46640?
To fix CVE-2024-46640, update to the latest version of SeaCMS where the vulnerability has been addressed.
3
What software is affected by CVE-2024-46640?
CVE-2024-46640 affects SeaCMS version 13.2.
4
What causes CVE-2024-46640?
CVE-2024-46640 is caused by a lack of execution of the check function during file operations in sql.class.chp.
5
Can CVE-2024-46640 be exploited remotely?
Yes, CVE-2024-46640 can be exploited remotely through MySQL slow query methods.