SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
The vulnerability is classified as CWE-404 (improper resource shutdown or release) and concerns improper handling of file resources in the admin_template.php file. An attacker, by sending a properly crafted network request, can specify any file on the server and cause its deletion. The lack of authentication requirement (PR:N) and user interaction (UI:N) means that the attack can be conducted remotely by any unauthorized person.
An attacker can permanently delete arbitrary files on the server, leading to a breach of application integrity and potential complete disruption (denial of service). It is also possible to delete critical configuration or system files, which may result in degradation or failure of the entire service.
Security patches available from the vendor should be applied in accordance with the references. Until the fix is implemented, it is recommended to restrict network access to the admin_template.php file (e.g., through firewall rules or web server configuration) and monitor logs for unauthorized requests to this resource.
SeaCMS version 12.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HSeacms
APPSeacms12.9
Related vulnerabilities
SQL injection w SeaCMS v13.3 — komponent admin_comment_news.php
SQL injection w SeaCMS v13.3 — komponent admin_topic.php
SQL injection w SeaCMS v13.3 — komponent admin_manager.php
RCE w SeaCMS v13.3 przez komponent phomebak.php
SQL injection w SeaCMS v13.3 — komponent admin_tempvideo.php