ZeroHour

CVE-2020-35276

PoC
CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

Vendors
egavilanmedia
Products
ecm address book
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.