Impact
SeaCMS versions up to 13.6 contain a flaw in the unlink function invoked by /member.php?action=chgpwdsubmit that allows an attacker to manipulate the "oldpic" parameter and delete arbitrary files. This path traversal vulnerability can lead to the removal of critical files or other assets on the server, potentially enabling further compromise. The weakness is a lack of proper input validation and is classified as CWE-22.
Affected Systems
All SeaCMS installations running version 13.6 or earlier are affected. This includes the member.php component that processes the oldpic argument for avatar uploads. No specific vendor sub‑products are listed beyond SeaCMS itself.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as the flaw can be exploited over HTTP by sending a crafted request to the vulnerable endpoint. Publicly available exploits exist, meaning that an attacker can readily target susceptible systems.
OpenCVE Enrichment