mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 14:19:30 +02:00
18 lines
715 B
Markdown
18 lines
715 B
Markdown
### [CVE-2020-35276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35276)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://hardik-solanki.medium.com/authentication-admin-panel-bypass-which-leads-to-full-admin-access-control-c10ec4ab4255
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|