CVE-2024-54880: Critical severity tina tinacms vulnerability
Published Jan 6, 2025
·Updated
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Affected Software
2 affected components
SEACMS SEACMS
SEACMS SEACMS=13.1
Event History
Jan 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54880?
CVE-2024-54880 is classified as a high severity vulnerability due to its potential for abuse in account registration.
2
How do I fix CVE-2024-54880?
To fix CVE-2024-54880, implement proper access controls to restrict bulk registration capabilities to authorized users only.
3
What are the implications of CVE-2024-54880?
The implications of CVE-2024-54880 include unauthorized bulk account creation, which can lead to resource abuse and data compromise.
4
Who is affected by CVE-2024-54880?
CVE-2024-54880 affects users of SeaCMS version 13.1 who do not have adequate access controls in place.
5
Can CVE-2024-54880 be exploited remotely?
Yes, attackers can exploit CVE-2024-54880 remotely to perform unauthorized bulk account registrations.