Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2020-18458

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
Attacker Value
Unknown

CVE-2020-18451

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.