CVE-2024-7161 is a Cross-Site Request Forgery (CSRF) vulnerability found in SeaCMS version 13.0, specifically within the password change functionality. An unauthenticated attacker can manipulate the 'newpwd' and 'newpwd2' arguments via a crafted request to force a user to change their password without their consent. This vulnerability has a CVSS score of 6.5 (Medium) due to its network-based attack vector and high impact on integrity, though it requires user interaction. While a public exploit has been disclosed, there is no evidence of active exploitation, nor are there Metasploit or Nuclei modules available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.0CPE matchmatch criteria | cpe:2.3:a:seacms:seacms:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.