Executive brief
SeaCMS is a content management system that allows authenticated users to upload profile avatars. A flaw in the avatar upload feature allows an authenticated attacker to delete arbitrary files on the server by crafting a malicious file path in the upload request, potentially leading to data loss or system compromise if critical files are targeted.
Technical details
This is a path traversal vulnerability combined with arbitrary file deletion in SeaCMS 13.6's member avatar upload functionality (/member.php?action=chgpwdsubmit). The vulnerable component fails to validate or sanitize the oldpic parameter before passing it directly to PHP's unlink() function. An authenticated, low-privileged member can bypass the deletion restriction by uploading a valid image while specifying a malicious oldpic path containing traversal sequences (e.g., ../../ or absolute paths), allowing deletion of files outside the intended uploads/user/ directory. The vulnerability requires the avatar upload feature to be enabled (cfg_upic='1') and an authenticated session; no additional user interaction is required. An attacker can delete arbitrary files writable by the web process, including application files, configuration files, or other user data.
Affected products
- SeaCMS SeaCMS up to 13.6
Timeline
- 2026-08-31: disclosed
- other: Public exploit available