CVE-2018-15844: Damicms
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
Affected products
- Damicms Damicms: version 6.0.0 only
Published 2018-08-25. Last modified 2026-06-17.