Cyber Posture

CVE-2025-25513

CriticalPublic PoC

Published: 24 February 2025

Published
24 February 2025
Modified
14 March 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0021 43.1th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may leverage databases to mine valuable information.

Security Summary

CVE-2025-25513 is a SQL injection vulnerability (CWE-89) in the admin_members.php component of SeaCMS versions 13.3 and earlier. Published on 2025-02-24, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical due to its potential for severe impact.

Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity and no requirement for user interaction. Exploitation grants high confidentiality, integrity, and availability impacts, enabling arbitrary SQL query execution that could result in data exfiltration, modification, or deletion.

The primary advisory reference is available at https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-1.md, which provides details on the issue but does not specify patches or mitigations in the CVE metadata.

Details

CWE(s)
CWE-89

Affected Products

seacms
seacms
≤ 13.3

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1213.006 Databases Collection
Adversaries may leverage databases to mine valuable information.
Why these techniques?

SQL injection in admin_members.php enables exploitation of a public-facing web application (T1190) and facilitates data collection from databases such as user/member information (T1213.006).

References