CVE-2025-15002: SeaCMS mysqli.class.php sql injection
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15002?
CVE-2025-15002 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-15002?
To fix CVE-2025-15002, upgrade SeaCMS to the latest version beyond 13.3 where the vulnerability is addressed.
What component is affected by CVE-2025-15002?
CVE-2025-15002 affects the mysqli.class.php file in the SeaCMS application.
Can CVE-2025-15002 be exploited remotely?
Yes, CVE-2025-15002 can be exploited remotely by manipulating the page/limit arguments.
What type of attack does CVE-2025-15002 enable?
CVE-2025-15002 enables SQL injection attacks which could compromise the database.