CVE-2018-19220: Laobancms
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
Affected products
- Laobancms Laobancms: version 2.0 only
Published 2018-11-12. Last modified 2026-06-17.