Vulnerabilities
Vulnerable Software
Seacms:  Security Vulnerabilities
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-05-28
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
CVSS Score
9.8
EPSS Score
0.084
Published
2020-12-21
SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.
CVSS Score
8.8
EPSS Score
0.004
Published
2019-02-17
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2018-11-17
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-11-17
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
CVSS Score
7.5
EPSS Score
0.012
Published
2018-09-26
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-09-22
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-09-21
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
CVSS Score
5.3
EPSS Score
0.004
Published
2018-09-21
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-09-16


Contact Us

Shodan ® - All rights reserved