CVE-2025-60449
03.10.2025, 14:15
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the applications source code but also potentially any file accessible on the servers root directory.Enginsight
| Vendor | Product | Version |
|---|---|---|
| seacms | seacms | 13.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration