Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-54879 PoC — SeaCMS 安全漏洞

Source
Associated Vulnerability
Title:SeaCMS 安全漏洞 (CVE-2024-54879)
Description:SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
Description
CVE-2024-54879
Readme
# 一、Project overview

| **item**                     | **content**                                       | **remark**          |
| ---------------------------- | ------------------------------------------------- | ------------------- |
| Authorized penetration range | http://192.168.88.141/                            | Local test          |
| Source code download         | https://www.seacms.net/SeaCMS_V13.1_install_f.zip | Open source project |
| Scope of vulnerability       | SeaCMS_V13.1                                      |                     |

# 二、Vulnerability description

## 1、Logic bug - Unlimited top-up members

| **category**                  | **content**                                                  | **remark** |
| ----------------------------- | ------------------------------------------------------------ | ---------- |
| Vulnerability location(URL) | http://192.168.200.141/member.php?action=hyz&gid=3&mon=1     |            |
| Vulnerability type            | Logic hole                                                   |            |
| Vulnerability description     | SeaCMS has a logical flaw that could be exploited by an attacker to allow any user to recharge members indefinitely |            |

***\*Visit a center and click on Super Member\****

![img](https://i-blog.csdnimg.cn/img_convert/ee7c71b70c61d9f9a27a6154d3b1b39e.jpeg)

***\*Click on 100 gold per month and grab the pack\****

![image-20241228233046755](https://i-blog.csdnimg.cn/img_convert/65f6abafa2133c5084f7f1259a079f51.png)

***\*If the gid parameter is changed to 1, the system returns that the recharge is successful\****

![image-20241228233155449](https://i-blog.csdnimg.cn/img_convert/004639270f39fac2dd4379f84129fb93.png)

***\*Refresh the Personal Center page, successfully add one month membership time\****

![image-20241228233211064](https://i-blog.csdnimg.cn/img_convert/5ef7e76a07c6a4be996cc10f3ef0aab2.png)

***\*Multiple packages, refresh the personal center page again, you can see the time lengthened\****

 

![image-20241228233238238](https://i-blog.csdnimg.cn/img_convert/8b4f559855faeb225d497002b394d5d5.png)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →