CVE-2026-82599 | SeaCMS up to 13.6 Avatar Upload member.php?action=chgpwdsubmit unlink oldpic path traversal
A vulnerability was found in SeaCMS up to 13.6 and classified as problematic. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal.
This vulnerability is referenced as CVE-2026-82599. It is possible to launch the attack remotely. Furthermore, an exploit is available.VulDB Recent EntriesRead More