CVE-2025-11071: SeaCMS Cron Task Management admin_cron.php sql injection
A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admincron.php of the component Cron Task Management Module. The manipulation of the argument resourcefrom/collectID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11071?
CVE-2025-11071 is rated as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-11071?
To fix CVE-2025-11071, you should update SeaCMS to the latest version that addresses this vulnerability.
What components are affected by CVE-2025-11071?
CVE-2025-11071 affects the Cron Task Management Module of SeaCMS in the file /admin_cron.php.
Can CVE-2025-11071 be exploited remotely?
Yes, CVE-2025-11071 can potentially be exploited remotely by manipulating specific parameters.
What type of attack does CVE-2025-11071 enable?
CVE-2025-11071 enables an SQL injection attack through the parameters resourcefrom and collectID.