CRITICAL🇵🇱 Wersja polska

CVE-2024-31611

CVSS 9.1v3.1pub. 2024-06-10upd. 2025-03-13

SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-404 (improper resource shutdown or release) and concerns improper handling of file resources in the admin_template.php file. An attacker, by sending a properly crafted network request, can specify any file on the server and cause its deletion. The lack of authentication requirement (PR:N) and user interaction (UI:N) means that the attack can be conducted remotely by any unauthorized person.

Impact

An attacker can permanently delete arbitrary files on the server, leading to a breach of application integrity and potential complete disruption (denial of service). It is also possible to delete critical configuration or system files, which may result in degradation or failure of the entire service.

Mitigation & patch

Security patches available from the vendor should be applied in accordance with the references. Until the fix is implemented, it is recommended to restrict network access to the admin_template.php file (e.g., through firewall rules or web server configuration) and monitor logs for unauthorized requests to this resource.

Who is affected

SeaCMS version 12.9

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Seacms

    APP
    Seacms
    12.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-44073CRITICAL9.8PL ✓same product

SQL injection w SeaCMS v13.3 — komponent admin_comment_news.php

CVE-2025-44074CRITICAL9.8PL ✓same product

SQL injection w SeaCMS v13.3 — komponent admin_topic.php

CVE-2025-44072CRITICAL9.8PL ✓same product

SQL injection w SeaCMS v13.3 — komponent admin_manager.php

CVE-2025-44071CRITICAL9.8PL ✓same product

RCE w SeaCMS v13.3 przez komponent phomebak.php

CVE-2025-29647CRITICAL9.8PL ✓same product

SQL injection w SeaCMS v13.3 — komponent admin_tempvideo.php