Description
A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component Password Change Handler. The manipulation of the argument newpwd/newpwd2 leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272575.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48129 | A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component Password Change Handler. The manipulation of the argument newpwd/newpwd2 leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272575. |
References
History
Thu, 19 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Seacms
Seacms seacms |
|
| CPEs | cpe:2.3:a:seacms:seacms:13.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Seacms
Seacms seacms |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T21:52:30.759Z
Reserved: 2024-07-27T20:14:02.230Z
Link: CVE-2024-7161
Updated: 2024-08-01T21:52:30.759Z
Status : Modified
Published: 2024-07-28T16:15:02.047
Modified: 2024-11-21T09:50:58.570
Link: CVE-2024-7161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD