PT-2025-19320 · Seacms · Seacms

Zonesec

·

Published

2025-05-05

·

Updated

2025-06-12

·

CVE-2025-4256

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SeaCMS version 13.2
Description A problematic vulnerability was found in SeaCMS, affecting unknown code of the file /admin paylog.php. The manipulation of the cstatus argument leads to cross-site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For SeaCMS version 13.2, consider disabling access to the /admin paylog.php file until a patch is available. Restrict the manipulation of the cstatus argument to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-4256

Affected Products

Seacms