Impact
SeaCMS versions up to 13.6 contain a flaw within the /ass.php script that allows an attacker to bypass normal authorization checks. By manipulating the request, an attacker can gain unauthorized access to privileged functionality or data that should be protected, without needing valid credentials. The vulnerability is classified as an improper authorization weakness (CWE-285) and a missing authorization failure (CWE-639).
Affected Systems
The vulnerability affects SeaCMS content management systems running any version up to and including 13.6. The exact affected version strings are not enumerated, so any installation built on SeaCMS 13.6 or earlier is potentially vulnerable. The primary file impacted is /ass.php, a part of the platform’s authorization logic.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact that can lead to unauthorized data exposure or control within the CMS. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Because the exploit can be triggered remotely, attackers can target web‑facing instances without prior access. No specific prerequisites are listed, so the risk remains significant for any exposed SeaCMS installation.
OpenCVE Enrichment