CVE-2024-55461: Command Injection
Published Dec 18, 2024
·Updated
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function EbakRepPathFiletext().
Affected Software
2 affected components
SEACMS SEACMS<=13.0
SEACMS SEACMS<=13.0
Event History
Dec 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-55461?
CVE-2024-55461 has been classified with a high severity level due to its capability of allowing command execution.
2
How do I fix CVE-2024-55461?
To fix CVE-2024-55461, you should upgrade SeaCMS to a version greater than 13.0 to eliminate the vulnerability.
3
What systems are affected by CVE-2024-55461?
CVE-2024-55461 affects all versions of SeaCMS up to and including version 13.0.
4
What is the impact of CVE-2024-55461?
The impact of CVE-2024-55461 includes the potential for remote attackers to execute arbitrary commands on the server.
5
Is CVE-2024-55461 being exploited in the wild?
As of now, there have been no confirmed reports of CVE-2024-55461 being actively exploited in the wild.