CVE-2018-15844: Damicms

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.

Affected products

  • Damicms Damicms: version 6.0.0 only

Published 2018-08-25. Last modified 2026-06-17.