CVE-2025-25794

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:seacms:seacms:13.3:*:*:*:*:*:*:*

History

28 Mar 2025, 17:00

Type Values Removed Values Added
First Time Seacms seacms
Seacms
CPE cpe:2.3:a:seacms:seacms:13.3:*:*:*:*:*:*:*
References () http://seacms.com - () http://seacms.com - Product
References () https://github.com/Ka7arotto/Seacms/blob/main/Seacms13.3-rce-4.md - () https://github.com/Ka7arotto/Seacms/blob/main/Seacms13.3-rce-4.md - Exploit, Third Party Advisory
References () https://www.seacms.com/ - () https://www.seacms.com/ - Product

06 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1
CWE CWE-77
Summary
  • (es) Se descubrió que SeaCMS v13.3 contiene una vulnerabilidad de ejecución remota de código (RCE) a través del componente admin_ping.php.

26 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 15:15

Updated : 2025-03-28 17:00


NVD link : CVE-2025-25794

Mitre link : CVE-2025-25794

CVE.ORG link : CVE-2025-25794


JSON object : View

Products Affected

seacms

  • seacms
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')