CVE-2023-44170

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 27, 2023

Summary

CVE-2023-44170 is a newly discovered vulnerability affecting SeaCMS V12.9. This issue allows an attacker to write arbitrary files through the admin_ping.php component, which can lead to serious data breaches or system compromise. An attacker can exploit this vulnerability by crafting a specially crafted request to write files outside the intended directory, potentially gaining unauthorized access to sensitive data or executing malicious code. This vulnerability poses a significant threat to websites using SeaCMS V12.9 and requires immediate attention and patching to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share