Remote Code Execution Vulnerability in SeaCMS v13.3 by SeaCMS
CVE-2025-25796

5.1MEDIUM

Key Information:

Vendor

SeaCMS

Status
Vendor
CVE Published:
26 February 2025

What is CVE-2025-25796?

A remote code execution vulnerability has been identified in SeaCMS v13.3, which allows an attacker to execute arbitrary code through the insecure component admin_template.php. This flaw poses a significant security risk, enabling potential unauthorized access and complete control over the affected application. Proper mitigation strategies should be implemented to secure affected installations against potential exploitation.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.