Arbitrary File Read Vulnerability in SeaCMS 13.3 by SeaCMS
CVE-2025-25800
5.3MEDIUM
Summary
An arbitrary file read vulnerability has been identified in SeaCMS 13.3, impacting the file_get_contents function in the admin_safe_file.php script. This flaw allows unauthorized users to access sensitive files on the server, potentially exposing critical data and configuration files. As a result, attackers could exploit this vulnerability to gain deeper access into the system, leading to further security breaches. Users are encouraged to apply necessary patches and review their security configurations to mitigate potential risks.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved