PT-2025-52613 · Seacms · Seacms

Yu22X

·

Published

2025-12-21

·

Updated

2025-12-30

·

CVE-2025-15002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeaCMS versions prior to 13.4
Description A flaw exists in SeaCMS that allows for SQL injection. The issue is located in an unknown function within the js/player/dmplayer/dmku/class/mysqli.class.php file. Manipulation of the page/limit argument can lead to exploitation. The attack can be carried out remotely, and the exploit is publicly available.
Recommendations Update SeaCMS to version 13.4 or later.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15002

Affected Products

Seacms