CVE-2025-25796

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:seacms:seacms:13.3:*:*:*:*:*:*:*

History

28 Mar 2025, 17:00

Type Values Removed Values Added
CPE cpe:2.3:a:seacms:seacms:13.3:*:*:*:*:*:*:*
First Time Seacms seacms
Seacms
References () http://seacms.com - () http://seacms.com - Product
References () https://github.com/Ka7arotto/Seacms/blob/main/Seacms13.3-rce-6.md - () https://github.com/Ka7arotto/Seacms/blob/main/Seacms13.3-rce-6.md - Exploit, Third Party Advisory
References () https://www.seacms.com/ - () https://www.seacms.com/ - Product

06 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1
Summary
  • (es) Se descubrió que SeaCMS v13.3 contiene una vulnerabilidad de ejecución remota de código (RCE) a través del componente admin_template.php.

26 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 15:15

Updated : 2025-03-28 17:00


NVD link : CVE-2025-25796

Mitre link : CVE-2025-25796

CVE.ORG link : CVE-2025-25796


JSON object : View

Products Affected

seacms

  • seacms
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')