CVE-2018-18083

CRITICAL

Comsenz Duomicms - Code Injection

Title source: rule
STIX 2.1

Description

An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.

Scores

CVSS v3 9.8
EPSS 0.0112
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
comsenz/duomicms 3.0
Published Oct 09, 2018
Tracked Since Feb 18, 2026