Exploits / Vulnerability Discovered : 2018-08-31 |
Type : webapps |
Platform : php
This exploit / vulnerability Damicms 6.0.0 crosssite request forgery (change admin password) is for educational purposes only and if it is used you will do on your own risk!
# Description:
# DamiCMS v6.0.0 allows CSRF to change the administrator account's pssword.
# After the administrator login in,open the poc,the administrator account's
# password will been changed to 123123