CVE-2024-40520: Seacms
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
Affected products
- Seacms Seacms: version 12.9 only
Published 2024-07-12. Last modified 2026-06-17.