Impact
A path traversal flaw exists in SeaCMS’s comment cache feature, triggered through the /member.php?action=del_pl endpoint when the itype or vid parameters are crafted with directory traversal characters. The flaw allows a remote attacker to reference arbitrary files on the server’s file system, potentially compromising confidentiality and providing a foothold for further exploitation. The vulnerability is rated moderate with a CVSS score of 5.3.
Affected Systems
SeaCMS releases 13.6 and older are impacted. The flaw resides in the comment cache component; releases newer than 13.6 are reported as not affected. Administrators should confirm whether their installations include the comment cache module and whether the /member.php script is reachable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. No EPSS score is available and the vulnerability has not been listed in the CISA KEV catalog, suggesting that large-scale automated exploitation has not been observed. However, the exploit is publicly available and can be performed remotely simply by supplying crafted query parameters to the del_pl action. Attackers could read arbitrary files from the web server, leading to data loss or defacement.
OpenCVE Enrichment