Impact
The vulnerability resides in the parseIf function of seacms_locoy_news.php in SeaCMS's Locoy Collector component. By manipulating the "pwd" argument, an attacker can inject arbitrary PHP code, which the application will execute. This potential to execute unintended code constitutes a remote code execution risk that could compromise system confidentiality, integrity, and availability.
Affected Systems
SeaCMS systems running version 13.6 or earlier are affected. The vulnerability is present in the Locoy Collector component of SeaCMS and applies to any deployment that uses the seacms_locoy_news.php file with the parseIf function.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the absence of an EPSS score means current exploitation likelihood is unknown. The vulnerability can be triggered remotely through crafted HTTP requests, and a publicly disclosed exploit exists, so attackers can potentially target vulnerable installations without authentication. Because the issue is not listed in the KEV catalog, it is not currently flagged as a known exploited vulnerability, but the available public exploit indicates a realistic threat.
OpenCVE Enrichment