SeaCMS 11.1 is vulnerable to stored cross-site scripting (XSS). An attacker can inject malicious JavaScript code into the checkuser parameter of the admin settings page, which will then execute in other users' browsers when they load the page.
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.