SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /adminreslib.php.
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component adminsafe.php.