CVE-2018-14910 describes a Remote Code Execution vulnerability in SeaCMS v6.61, allowing attackers to execute arbitrary PHP code by injecting it into an allowed IP address field within the admin_ip.php page. This vulnerability has a CVSS score of 8.8 (High), indicating a critical risk due to its low attack complexity and high impact on confidentiality, integrity, and availability, and can also be exploited via CSRF. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) is currently reported, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.61CPE matchmatch criteria | cpe:2.3:a:seacms:seacms:6.61:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.