Skip to content
COOEY

EXPOSURES › CVE-2020-35276

CVE-2020-35276

CRITICAL
DETAIL
SourceNVD · cve Published2020-12-21 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-35276 ↗
SHAME 35/100

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.50
Vulnerability confirmed but no vendor response or remediation details found in sources.
cooey ↗ severe-fallout -0.80
Vulnerability confirmed with high impact (SQLi bypassing admin login)
"An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user."
www.cvefind.com ↗ severe-fallout +0.00
Neutral listing of CVE data
The Hacker News ↗ severe-fallout +0.00
Irrelevant article about Microsoft 365 phishing
www.cbc.ca ↗ severe-fallout +0.00
Irrelevant article about child exploitation
CISA ↗ severe-fallout +0.00
Irrelevant CISA ICS advisories page
dailysecurityreview.com ↗ severe-fallout +0.00
Irrelevant article about Roundcube webmail
dailysecurityreview.com ↗ severe-fallout +0.00
Irrelevant article about Cloudflare developer domains
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.