ZeroHour

CVE-2018-16239

PoC
CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.

Vendors
damicms
Products
damicms
Weakness
CWE-330
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.