CVE-2025-25797
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Published Feb 26, 2025
Updated: Mar 6, 2025
CWE ID 77
Summary
CVE-2025-25797 represents a remote code execution (RCE) vulnerability found in SeaCMS version 13.3. The affected component is identified as admin_smtp.php. Successful exploitation of this flaw allows attackers to execute arbitrary code on the targeted system, potentially leading to serious security consequences. System administrators are advised to promptly update their SeaCMS installation to a non-vulnerable version. Failure to address this issue in a timely manner may result in unauthorized system access and data compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SeaCMS
Affected Vendors
- Seacms