CVE-2025-3792: SeaCMS admin_link.php sql injection
Published Apr 18, 2025
·Updated
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /adminlink.php?action=delall. The manipulation of the argument eid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
SEACMS SEACMS<=13.3
SEACMS SEACMS<=13.3
Event History
Apr 18, 2025
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3792?
CVE-2025-3792 is classified as a critical vulnerability.
2
What does CVE-2025-3792 affect?
CVE-2025-3792 affects SeaCMS versions up to 13.3.
3
What kind of vulnerability is CVE-2025-3792?
CVE-2025-3792 is a SQL injection vulnerability found in the /admin_link.php?action=delall file.
4
How can CVE-2025-3792 be exploited?
CVE-2025-3792 can be exploited remotely by manipulating the e_id argument.
5
How do I fix CVE-2025-3792?
To fix CVE-2025-3792, update SeaCMS to a version beyond 13.3 where the vulnerability is patched.