{ "id": "CVE-2024-42598", "sourceIdentifier": "cve@mitre.org", "published": "2024-08-20T16:15:11.727", "lastModified": "2024-08-20T16:15:11.727", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges." } ], "metrics": {}, "references": [ { "url": "https://gitee.com/fushuling/cve/blob/master/SeaCMS%20V13%20admin_editplayer.php%20code%20injection.md", "source": "cve@mitre.org" } ] }