CVE-2025-25515: SQL Injection
Published Feb 25, 2025
·Updated
Seacms <=13.3 is vulnerable to SQL Injection in admincollect.php that allows an authenticated attacker to exploit the database.
Affected Software
2 affected components
SEACMS SEACMS<=13.3
SEACMS SEACMS<=13.3
Event History
Feb 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25515?
CVE-2025-25515 is classified as a high-severity SQL Injection vulnerability that can be exploited by authenticated attackers.
2
How do I fix CVE-2025-25515?
To fix CVE-2025-25515, update Seacms to version 13.4 or later to mitigate the SQL Injection vulnerability.
3
Who is affected by CVE-2025-25515?
Any users or organizations running Seacms version 13.3 or earlier are affected by CVE-2025-25515.
4
What type of attack can exploit CVE-2025-25515?
CVE-2025-25515 can be exploited through SQL Injection attacks, allowing unauthorized access to the database.
5
What files are involved in CVE-2025-25515?
The vulnerable file associated with CVE-2025-25515 is admin_collect.php in Seacms.