PT-2026-83670 · Seacms · Seacms
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SeaCMS versions prior to 13.7
Description
A security flaw allows remote attackers to perform SQL injection, a technique used to interfere with the queries that an application makes to its database. The issue exists in the
/zyapi.php?ac=videolist endpoint when manipulating the ids variable.Recommendations
Update SeaCMS to a version later than 13.6.
As a temporary workaround, restrict access to the
/zyapi.php?ac=videolist endpoint or avoid using the ids variable until the software is updated.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Seacms