DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
- https://github.com/doramart/DoraCMS/issues/256
No PoCs found on GitHub currently.