PoC Index

CVE-2020-35276

CRITICAL 9.8EPSS 1.5%

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.54% chance of exploitation in the next 30 days, 73th percentile
Published
2020-12-21
Updated
2026-07-09

Proof-of-concept exploits (1)

References

Related