Vendor CVEs
Seacms
All CVEs
125 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43278 | Hig | 0.57 | 8.8 | 0.00 | Sep 25, 2023 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account. | ||
| CVE-2019-8418 | Hig | 0.57 | 8.8 | 0.01 | Feb 17, 2019 | SeaCMS 7.2 mishandles member.php?mod=repsw4 requests. | ||
| CVE-2018-14910 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2018 | SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF. | ||
| CVE-2018-14421 | Hig | 0.57 | 8.8 | 0.01 | Jul 20, 2018 | SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF. | ||
| CVE-2018-13445 | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2018 | An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add. | ||
| CVE-2018-13444 | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2018 | An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2. | ||
| CVE-2023-44848 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component. | ||
| CVE-2024-44720 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2024 | SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php. | ||
| CVE-2024-39027 | Hig | 0.49 | 7.5 | 0.00 | Jul 5, 2024 | SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked. | ||
| CVE-2018-17365 | Hig | 0.49 | 7.5 | 0.02 | Sep 26, 2018 | SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter. | ||
| CVE-2018-16446 | Hig | 0.49 | 7.5 | 0.02 | Sep 4, 2018 | An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt. | ||
| CVE-2026-85138 | Hig | 0.47 | 7.3 | 0.00 | Sep 3, 2026 | A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public… | ||
| CVE-2026-85137 | Hig | 0.47 | 7.3 | 0.00 | Sep 3, 2026 | A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit… | ||
| CVE-2026-82600 | Hig | 0.47 | 7.3 | 0.00 | Aug 31, 2026 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2026-82598 | Hig | 0.47 | 7.3 | 0.00 | Aug 31, 2026 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2025-15002 | Hig | 0.47 | 7.3 | 0.00 | Dec 21, 2025 | A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has… | ||
| CVE-2024-44916 | Hig | 0.47 | 7.2 | 0.01 | Aug 30, 2024 | Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution. | ||
| CVE-2023-44847 | Hig | 0.47 | 7.2 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component. | ||
| CVE-2022-48093 | Hig | 0.47 | 7.2 | 0.01 | Feb 1, 2023 | Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php. | ||
| CVE-2022-28076 | Hig | 0.47 | 7.2 | 0.02 | May 4, 2022 | Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings. | ||
| CVE-2018-19349 | Hig | 0.47 | 7.2 | 0.01 | Nov 17, 2018 | In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php. | ||
| CVE-2018-16343 | Hig | 0.47 | 7.2 | 0.02 | Sep 2, 2018 | SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS. | ||
| CVE-2017-17561 | Hig | 0.47 | 7.2 | 0.01 | Dec 12, 2017 | SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php. | ||
| CVE-2024-42598 | Med | 0.44 | 6.7 | 0.01 | Aug 20, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the… | ||
| CVE-2024-40570 | Med | 0.42 | 6.5 | 0.00 | Jun 17, 2025 | SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component. | ||
| CVE-2025-25514 | Med | 0.42 | 6.5 | 0.00 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. | ||
| CVE-2024-39036 | Med | 0.42 | 6.5 | 0.01 | Jul 16, 2024 | SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php. | ||
| CVE-2020-28846 | Med | 0.42 | 6.5 | 0.00 | Aug 17, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account. | ||
| CVE-2024-6416 | Med | 0.41 | 6.3 | 0.01 | Jun 30, 2024 | A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to… | ||
| CVE-2020-36932 | Med | 0.40 | 6.1 | 0.00 | Jan 25, 2026 | SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded. | ||
| CVE-2024-44920 | Med | 0.40 | 6.1 | 0.00 | Sep 3, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter. | ||
| CVE-2024-44683 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2024 | Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. | ||
| CVE-2021-29313 | Med | 0.40 | 6.1 | 0.01 | Aug 17, 2021 | Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php, | ||
| CVE-2020-26642 | Med | 0.40 | 6.1 | 0.01 | May 28, 2021 | A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML. | ||
| CVE-2018-17321 | Med | 0.40 | 6.1 | 0.01 | Sep 22, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action. | ||
| CVE-2018-17062 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. | ||
| CVE-2018-14517 | Med | 0.40 | 6.1 | 0.01 | Jul 23, 2018 | SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields. | ||
| CVE-2018-11583 | Med | 0.40 | 6.1 | 0.01 | May 31, 2018 | SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter. | ||
| CVE-2025-25799 | Med | 0.39 | 6.0 | 0.00 | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php. | ||
| CVE-2026-82603 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The… | ||
| CVE-2026-82599 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the… | ||
| CVE-2025-50592 | Med | 0.35 | 5.4 | 0.00 | Aug 5, 2025 | Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player. | ||
| CVE-2024-44919 | Med | 0.35 | 5.4 | 0.00 | Aug 29, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter. | ||
| CVE-2023-50470 | Med | 0.35 | 5.4 | 0.00 | Dec 28, 2023 | A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37125 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37124 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-2926 | Med | 0.35 | 5.4 | 0.01 | May 27, 2023 | A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated… | ||
| CVE-2018-19350 | Med | 0.35 | 5.4 | 0.01 | Nov 17, 2018 | In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. | ||
| CVE-2018-16821 | Med | 0.35 | 5.3 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. | ||
| CVE-2026-82602 | Med | 0.34 | 5.3 | 0.00 | Aug 31, 2026 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
- risk 0.57cvss 8.8epss 0.01
SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.
- risk 0.57cvss 8.8epss 0.01
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF.
- risk 0.57cvss 8.8epss 0.01
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.
- risk 0.53cvss 8.1epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.
- risk 0.49cvss 7.5epss 0.01
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
- risk 0.49cvss 7.5epss 0.00
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.
- risk 0.49cvss 7.5epss 0.02
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…
- risk 0.47cvss 7.3epss 0.00
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has…
- risk 0.47cvss 7.2epss 0.01
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
- risk 0.47cvss 7.2epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
- risk 0.47cvss 7.2epss 0.01
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
- risk 0.47cvss 7.2epss 0.02
Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
- risk 0.47cvss 7.2epss 0.01
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
- risk 0.47cvss 7.2epss 0.02
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
- risk 0.47cvss 7.2epss 0.01
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.
- risk 0.44cvss 6.7epss 0.01
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…
- risk 0.42cvss 6.5epss 0.00
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.
- risk 0.42cvss 6.5epss 0.00
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
- risk 0.42cvss 6.5epss 0.01
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
- risk 0.42cvss 6.5epss 0.00
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to…
- risk 0.40cvss 6.1epss 0.00
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
- risk 0.40cvss 6.1epss 0.00
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
- risk 0.39cvss 6.0epss 0.00
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
- risk 0.35cvss 5.4epss 0.00
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The…
- risk 0.35cvss 5.4epss 0.00
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the…
- risk 0.35cvss 5.4epss 0.00
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated…
- risk 0.35cvss 5.4epss 0.01
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
- risk 0.35cvss 5.3epss 0.01
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
- risk 0.34cvss 5.3epss 0.00
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Page 2 of 3