CVE-2018-16338: Auracms
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
Affected products
- Auracms Auracms: version 2.3 only
Published 2018-09-02. Last modified 2026-06-17.