CVE-2025-60449: Infoleak
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the adminsafe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source code but also potentially any file accessible on the server’s root directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60449?
CVE-2025-60449 is classified as an information disclosure vulnerability that can expose sensitive application data.
How do I fix CVE-2025-60449?
To fix CVE-2025-60449, update SeaCMS to the latest version or apply any patches provided by the vendor.
Who is affected by CVE-2025-60449?
CVE-2025-60449 affects users running SeaCMS version 13.1.
What components are involved in CVE-2025-60449?
The vulnerability is located in the admin_safe.php component within the /btcoan/ directory of SeaCMS.
What can attackers do with CVE-2025-60449?
Attackers with authenticated access can exploit CVE-2025-60449 to scan and download the application's source code and potentially sensitive information.