CVE-2018-16239: Damicms
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
Affected products
- Damicms Damicms: version 6.0.1 only
Published 2018-08-30. Last modified 2026-06-17.