CVE-2025-25797: Command Injection
Published Feb 26, 2025
·Updated
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminsmtp.php.
Affected Software
2 affected components
SEACMS SEACMS
SEACMS SEACMS=13.3
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25797?
CVE-2025-25797 has been classified as a high-severity remote code execution vulnerability.
2
How do I fix CVE-2025-25797?
To fix CVE-2025-25797, update SeaCMS to the latest version that addresses this vulnerability.
3
What component is affected by CVE-2025-25797?
CVE-2025-25797 affects the admin_smtp.php component of SeaCMS v13.3.
4
Can CVE-2025-25797 allow unauthorized access?
Yes, CVE-2025-25797 can potentially allow unauthorized users to execute arbitrary code remotely.
5
Is CVE-2025-25797 specific to a certain version of SeaCMS?
Yes, CVE-2025-25797 specifically affects SeaCMS version 13.3.