CVE-2018-7308: Hosting Project Hosting

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.

Affected products

Published 2018-02-21. Last modified 2026-06-17.