在 SeaCMS 13.6 及更早版本中发现了一个漏洞。该漏洞影响了 Avatar Upload 组件中 /member.php?action=chgpwdsubmit 文件的 unlink 函数。对参数 oldpic 的特异操作会导致路径遍历(path traversal)问题。该攻击可远程发起,且利用工具已公开可用,存在被利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | SeaCMS | 13.0 |
cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
No comments yet