CVE-2024-52725: SQL Injection
Published Nov 20, 2024
·Updated
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMSSeoAndTag.php component.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms=4.8
Event History
Nov 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52725?
CVE-2024-52725 is classified as a critical severity vulnerability due to its ability to allow arbitrary code execution.
2
How do I fix CVE-2024-52725?
To fix CVE-2024-52725, update to the latest version of SemCms that addresses this SQL injection vulnerability.
3
What component of SemCms is affected by CVE-2024-52725?
CVE-2024-52725 affects the SEMCMS_SeoAndTag.php component in SemCms v4.8.
4
What kind of attack can be executed using CVE-2024-52725?
CVE-2024-52725 allows an attacker to execute arbitrary code via a crafted ldgid parameter.
5
Which versions of SemCms are vulnerable to CVE-2024-52725?
SemCms v4.8 is known to be vulnerable to CVE-2024-52725.