CVE-2025-25792: Command Injection
Published Feb 26, 2025
·Updated
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at adminweixin.php.
Affected Software
2 affected components
SEACMS SEACMS
SEACMS SEACMS=13.3
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25792?
CVE-2025-25792 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2025-25792?
To mitigate CVE-2025-25792, update SeaCMS to the latest patched version that addresses this vulnerability.
3
What systems are affected by CVE-2025-25792?
CVE-2025-25792 affects SeaCMS version 13.3 specifically in the context of the admin_weixin.php file.
4
Can CVE-2025-25792 be exploited remotely?
Yes, CVE-2025-25792 can be exploited remotely through the isopen parameter.
5
What are the potential consequences of CVE-2025-25792?
Exploitation of CVE-2025-25792 can lead to unauthorized remote code execution on affected systems.