Vulnerability Description
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Damicms | Damicms | 6.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/howchen/howchen/issues/2ExploitThird Party Advisory
- https://github.com/howchen/howchen/issues/2ExploitThird Party Advisory
FAQ
What is CVE-2018-16239?
CVE-2018-16239 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
How severe is CVE-2018-16239?
CVE-2018-16239 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-16239?
Check the references section above for vendor advisories and patch information. Affected products include: Damicms Damicms.