{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-82599","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-08-30T06:42:07.879Z","datePublished":"2026-08-31T00:45:08.847Z","dateUpdated":"2026-08-31T16:11:27.010Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-08-31T00:45:08.847Z"},"title":"SeaCMS Avatar Upload member.php unlink path traversal","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-22","lang":"en","description":"Path Traversal"}]}],"affected":[{"vendor":"n/a","product":"SeaCMS","versions":[{"version":"13.0","status":"affected"},{"version":"13.1","status":"affected"},{"version":"13.2","status":"affected"},{"version":"13.3","status":"affected"},{"version":"13.4","status":"affected"},{"version":"13.5","status":"affected"},{"version":"13.6","status":"affected"}],"cpes":["cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*"],"modules":["Avatar Upload"]}],"descriptions":[{"lang":"en","value":"A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5.5,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-08-30T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-08-30T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-08-30T08:47:23.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"T-Chachamaru (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/397101","name":"VDB-397101 | SeaCMS Avatar Upload member.php unlink path traversal","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/397101/cti","name":"VDB-397101 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-82599","name":"CVE-2026-82599 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/892780","name":"Submit #892780 | SeaCMS 13.6 Path Traversal","tags":["third-party-advisory"]},{"url":"https://github.com/T-Chachamaru/seacms-13.6-security-advisories/blob/a084a3e573240d54860153321df271280daec262/c-002b-member-oldpic-file-deletion.md","tags":["exploit"]}],"tags":["x_freeware"],"x_generator":["VulDB PVTS v202608"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-31T16:11:15.824938Z","id":"CVE-2026-82599","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-31T16:11:27.010Z"}}]}}