Impact
An authenticated remote code execution vulnerability exists within the admin_config.php component of seacms version 13.6. By sending a specially crafted POST request, an attacker who has authenticated credentials can execute arbitrary code on the server. This flaw compromises the confidentiality, integrity, and availability of the affected system, allowing full control over the hosting environment.
Affected Systems
The vulnerability is limited to seacms version 13.6. No additional product or vendor variants are listed. Deployments running this version with an administrator or privileged account exposed to the internet are at risk.
Risk and Exploitability
The flaw requires authentication but can be triggered over the web. The CVSS score is 8.8, indicating a high‑severity risk, and the EPSS score is < 1% with no listing in the CISA KEV catalog. Nevertheless, the ability to execute code remotely makes it a high‑severity risk. Attackers with legitimate credentials can target the admin_config.php endpoint directly, bypassing other controls or attempting to subvert authentication mechanisms. The lack of a public exploit record does not diminish the potential impact of an in‑house or targeted attack.
OpenCVE Enrichment