EXPOSURES › CVE-2020-35276
CVE-2020-35276
CRITICAL
DETAIL
SourceNVD · cve
Published2020-12-21
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-35276 ↗
SHAME 35/100
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.50
Vulnerability confirmed but no vendor response or remediation details found in sources.
Vulnerability confirmed with high impact (SQLi bypassing admin login)
"An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user."
Neutral listing of CVE data
Irrelevant article about Microsoft 365 phishing
Irrelevant article about child exploitation
Irrelevant CISA ICS advisories page
Irrelevant article about Roundcube webmail
Irrelevant article about Cloudflare developer domains
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.