CVE-2018-7308: Hosting Project Hosting
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.
Affected products
- Hosting Project Hosting: up to and including 2018-02-11
Published 2018-02-21. Last modified 2026-06-17.