CVE-2025-25802
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Published Feb 26, 2025
Updated: Mar 6, 2025
CWE ID 77
Summary
CVE-2025-25802 is a newly identified remote code execution (RCE) vulnerability affecting SeaCMS version 13.3. Hackers can exploit this flaw by targeting the admin_ip.php component, enabling them to execute arbitrary code on affected systems. Successful attacks could result in unauthorized access to sensitive data or even complete system takeover. It is strongly recommended that users of SeaCMS v13.3 upgrade to a secure version immediately to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SeaCMS
Affected Vendors
- Seacms