Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-54880 PoC — SeaCMS 安全漏洞

Source
Associated Vulnerability
Title: SeaCMS 安全漏洞 (CVE-2024-54880)
Description:SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Description
CVE-2024-54880
Readme
# 一、Project overview

| **item**                     | **content**                                       | **remark**          |
| ---------------------------- | ------------------------------------------------- | ------------------- |
| Authorized penetration range | http://192.168.88.141/                            | Local test          |
| Source code download         | https://www.seacms.net/SeaCMS_V13.1_install_f.zip | Open source project |
| Scope of vulnerability       | SeaCMS_V13.1                                      |                     |

# 一、Vulnerability description

## 1、Logic vulnerability - Registering accounts in bulk

| **category**                  | **content**                                                  | **remark** |
| ----------------------------- | ------------------------------------------------------------ | ---------- |
| Vulnerability location(URL) | http://192.168.200.141/reg.php?action=reg                    |            |
| Vulnerability type            | Logic hole                                                   |            |
| Vulnerability description     | SeaCMS has a logical flaw that could be exploited by an attacker to allow any user to register accounts in bulk |            |

**Visit the registration page and click Register to capture the package (this is the photo added later)**

![image-20241228231116461](https://gitee.com/ileny/blog-img/raw/master/image/image-20241228231116461.png)

***\*The verification code here is 14\****

![image-20241228231126473](https://gitee.com/ileny/blog-img/raw/master/image/image-20241228231126473.png)

***\*Change your account number and email address\****

![image-20241228231135449](https://gitee.com/ileny/blog-img/raw/master/image/image-20241228231135449.png)

***\*Try logging in to the first account here\****

![img](https://gitee.com/ileny/blog-img/raw/master/image/wps9.jpg) 

***\*Try to log in to the second account\****

![image-20241228231151045](https://gitee.com/ileny/blog-img/raw/master/image/image-20241228231151045.png)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →