Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-54879 — CVE-2024-54879 | Kitploit
Tools/GitHubGitHub/ailenye/cve-2024-54879
Vulnerability AnalysisWeb Application ExploitationPenetration TestingMisconfigurationLearning & Education
GitHubailenye/cve-2024-54879

CVE-2024-54879

CVE-2024-54879

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

一、Project overview

二、Vulnerability description

1、Logic bug - Unlimited top-up members

categorycontent

*Visit a center and click on Super Member*

img

*Click on 100 gold per month and grab the pack*

image-20241228233046755

*If the gid parameter is changed to 1, the system returns that the recharge is successful*

image-20241228233155449

*Refresh the Personal Center page, successfully add one month membership time*

image-20241228233211064

*Multiple packages, refresh the personal center page again, you can see the time lengthened*

image-20241228233238238

Download Tool
itemcontentremark
Authorized penetration rangehttp://192.168.88.141/Local test
Source code downloadhttps://www.seacms.net/SeaCMS_V13.1_install_f.zipOpen source project
Scope of vulnerabilitySeaCMS_V13.1
remark
Vulnerability location(URL)http://192.168.200.141/member.php?action=hyz&gid=3&mon=1
Vulnerability typeLogic hole
Vulnerability descriptionSeaCMS has a logical flaw that could be exploited by an attacker to allow any user to recharge members indefinitely