CVE-2018-16608: Monstra

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR).

Affected products

  • Monstra Monstra: version 3.0.4 only

Published 2018-09-10. Last modified 2026-06-17.