An issue in SeaCMS v.12.9 allows an malicious user to execute arbitrary commands via the admin_safe.php component.
seacms seacms