SeaCMS Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SeaCMS versions through 13.2. This issue allows attackers to perform reflected XSS attacks by exploiting the vid parameter in a specific route, potentially leading authenticated users to execute arbitrary JavaScript code.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a GET request to the Upload/js/player/dmplayer/player route with a crafted vid parameter that includes JavaScript payloads, such as script tags or image tags with event handlers. The injected script will execute an alert as a demonstration of the XSS attack.

Added: Aug 5, 2025, 8:22 PM
Updated: Aug 5, 2025, 10:11 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
7.9
remediation
7.7
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.