First published: Mon May 05 2025(Updated: )
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4257 is classified as a problematic vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2025-4257, ensure proper input validation and output encoding in the processing of the /admin_pay.php file.
CVE-2025-4257 affects users of SeaCMS version 13.2 that utilize the /admin_pay.php file.
CVE-2025-4257 can be exploited to perform cross-site scripting (XSS) attacks remotely.
Yes, CVE-2025-4257 can be exploited remotely, potentially without any authentication.