PT-2018-14339 · Duomi · Duomicms

Mochazz

·

Published

2018-10-09

·

Updated

2020-06-17

·

CVE-2018-18084

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DuomiCMS version 3.0
Description An issue exists in the software, specifically a SQL injection in the ajax.php file. This is demonstrated by the uid parameter.
Recommendations For DuomiCMS version 3.0, consider restricting access to the ajax.php file or avoiding the use of the uid parameter until a fix is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18084

Affected Products

Duomicms