CVE-2025-45752

HIGH

SeedDMS 6.0.32 - Authenticated Remote Code Execution via Zip Import in Extension Manager

Title source: llm
STIX 2.1

Description

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.

Scores

CVSS v3 7.2
EPSS 0.0049
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
seeddms/seeddms 6.0.32
Published May 21, 2025
Tracked Since Feb 18, 2026