CVE-2024-46640: Seacms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.

Affected products

  • Seacms Seacms: version 13.2 only

Published 2024-09-20. Last modified 2026-06-17.