CVE-2024-6416
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Jun 30, 2024
Updated: Jul 1, 2024
CWE ID 89
Summary
CVE-2024-6416 is a newly disclosed critical vulnerability in SeaCMS 12.9. This issue affects an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. An attacker can exploit this vulnerability by manipulating the argument cid with the input (select(0)from(select(sleep(10)))v), leading to SQL injection. This attack can be launched remotely, making it a significant threat. The exploit for this vulnerability has been disclosed to the public, increasing the risk of widespread usage. The associated identifier for this vulnerability is VDB-270007.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- SeaCMS