CVE-2025-60449
EUVD-2025-3249503.10.2025, 14:15
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source code but also potentially any file accessible on the server’s root directory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| seacms | seacms | 13.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration