Vulnerabilities (CVE)

Filtered by vendor Damicms Subscribe
Filtered by product Damicms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21236 1 Damicms 1 Damicms 2022-01-10 6.8 MEDIUM 8.8 HIGH
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
CVE-2020-18458 1 Damicms 1 Damicms 2021-08-17 6.0 MEDIUM 8.0 HIGH
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
CVE-2018-13031 1 Damicms 1 Damicms 2021-06-17 6.8 MEDIUM 8.8 HIGH
DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
CVE-2018-20571 1 Damicms 1 Damicms 2019-01-11 5.0 MEDIUM 7.5 HIGH
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.
CVE-2018-16331 1 Damicms 1 Damicms 2018-10-23 6.8 MEDIUM 8.8 HIGH
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
CVE-2018-16238 1 Damicms 1 Damicms 2018-10-19 6.5 MEDIUM 7.2 HIGH
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.
CVE-2018-15844 1 Damicms 1 Damicms 2018-10-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.