Cross Site Scripting Vulnerability in SeaCMS by SeaCMS
CVE-2025-50592

5.4MEDIUM

Key Information:

Vendor

SeaCMS

Status
Vendor
CVE Published:
5 August 2025

What is CVE-2025-50592?

A cross site scripting vulnerability exists in SeaCMS versions prior to 13.2, specifically through the 'vid' parameter in the Upload/js/player/dmplayer/player endpoint. This flaw could allow attackers to inject malicious scripts into web pages viewed by users. When exploited, it can lead to unauthorized access to sensitive information, session hijacking, or other malicious actions. Users and administrators of vulnerable versions are advised to upgrade to mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.