Cross Site Scripting Vulnerability in SeaCMS by SeaCMS
CVE-2025-50592
5.4MEDIUM
What is CVE-2025-50592?
A cross site scripting vulnerability exists in SeaCMS versions prior to 13.2, specifically through the 'vid' parameter in the Upload/js/player/dmplayer/player endpoint. This flaw could allow attackers to inject malicious scripts into web pages viewed by users. When exploited, it can lead to unauthorized access to sensitive information, session hijacking, or other malicious actions. Users and administrators of vulnerable versions are advised to upgrade to mitigate this risk.