ZeroHour

CVE-2020-35737

PoC ×2
CVSS 3.1
7.5 high
EPSS
10%p95
Published
()
Modified
Description

In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

Vendors
newgensoft
Products
egov
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.