CVE-2025-25513
Published: 24 February 2025
Description
Adversaries may leverage databases to mine valuable information.
Security Summary
CVE-2025-25513 is a SQL injection vulnerability (CWE-89) in the admin_members.php component of SeaCMS versions 13.3 and earlier. Published on 2025-02-24, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical due to its potential for severe impact.
Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity and no requirement for user interaction. Exploitation grants high confidentiality, integrity, and availability impacts, enabling arbitrary SQL query execution that could result in data exfiltration, modification, or deletion.
The primary advisory reference is available at https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-1.md, which provides details on the issue but does not specify patches or mitigations in the CVE metadata.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
SQL injection in admin_members.php enables exploitation of a public-facing web application (T1190) and facilitates data collection from databases such as user/member information (T1213.006).