CVE-2025-60449

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/10/2025
Last modified:
08/10/2025

Description

An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source code but also potentially any file accessible on the server’s root directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:seacms:seacms:13.1:*:*:*:*:*:*:*