PT-2026-83646 · Seacms · Seacms
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SeaCMS versions prior to 13.7
Description
Remote code injection is possible within the Template Engine component due to improper handling of the
searchtype argument in the parseIf() function of the search.php file.Recommendations
Update SeaCMS to version 13.7 or later.
As a temporary mitigation, restrict access to the
search.php file or avoid using the searchtype parameter.Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Seacms