SeaCMS
cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*
- <= 11.1
A stored cross-site scripting vulnerability has been identified in SeaCMS version 11.1. The issue resides in the 'checkuser' parameter of the admin settings page, allowing attackers to inject malicious JavaScript that executes in the browsers of users who load the page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, navigate to the admin settings page and inject a script payload into the 'checkuser' parameter. Once the payload is submitted, it will be executed in the browser when the page is loaded.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.