New Path Traversal Vulnerability (CVE-2026-82599) Disclosed in SeaCMS
A path traversal vulnerability (CVE-2026-82599) has been identified in SeaCMS up to version 13.6. The flaw exists in the `unlink` function within the `/member.php?action=chgpwdsubmit` file, specifically in the Avatar Upload component. Manipulation of the `oldpic` argument can lead to remote exploitation, and an exploit is publicly available.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.