Логотип exploitDog
bind:CVE-2020-37008
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-37008

Количество 2

Количество 2

nvd логотип

CVE-2020-37008

10 дней назад

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g34j-q536-5j2m

10 дней назад

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-37008

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

CVSS3: 7.5
0%
Низкий
10 дней назад
github логотип
GHSA-g34j-q536-5j2m

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

CVSS3: 7.5
0%
Низкий
10 дней назад

Уязвимостей на страницу