CVE-2025-10662: SeaCMS admin_members.php sql injection
A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /adminmembers.php?ac=editsave. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This affects another injection point than CVE-2025-25513.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10662?
CVE-2025-10662 has a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-10662?
To fix CVE-2025-10662, update SeaCMS to version 13.4 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2025-10662?
CVE-2025-10662 is an SQL injection vulnerability that can be exploited through manipulating the ID argument.
Who is affected by CVE-2025-10662?
CVE-2025-10662 affects users of SeaCMS versions up to and including 13.3.
Can CVE-2025-10662 be exploited remotely?
Yes, CVE-2025-10662 can be exploited remotely, allowing attackers to execute SQL queries.