CVE-2025-6864: SeaCMS admin_type.php cross-site request forgery
Published Jun 29, 2025
·Updated
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admintype.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
SEACMS SEACMS<=13.2
SEACMS SEACMS<=13.2
Event History
Jun 29, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 30, 57482
Event
via FIRST·12:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6864?
CVE-2025-6864 is classified as a problematic vulnerability affecting SeaCMS up to version 13.2.
2
What type of vulnerability is CVE-2025-6864?
CVE-2025-6864 is a cross-site request forgery (CSRF) vulnerability.
3
Is remote exploitation possible with CVE-2025-6864?
Yes, CVE-2025-6864 can be exploited remotely.
4
How do I fix CVE-2025-6864?
To fix CVE-2025-6864, upgrade SeaCMS to a version later than 13.2.
5
What file is affected by CVE-2025-6864?
CVE-2025-6864 affects the functionality of the file /admin_type.php in SeaCMS.