CVE-2017-17561 describes a critical vulnerability in SeaCMS 6.56, allowing remote authenticated administrators to execute arbitrary PHP code. This is achieved by injecting a crafted token field into admin/admin_ping.php, which then interacts with data/admin/ping.php. The vulnerability carries a CVSS score of 7.2 (High), indicating a severe impact with high confidentiality, integrity, and availability compromise, requiring high privileges but no user interaction. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.56CPE matchmatch criteria | cpe:2.3:a:seacms_project:seacms:6.56:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.