CVE-2020-35276: SQL Injection

Published Dec 21, 2020
·
Updated

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

Affected Software

1 affected component
EGavilanMedia ECM Address Book=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade EgavilanMedia ECM Address Book to a version that resolves this vulnerability.

    Fixed in 1.0

Event History

Dec 21, 2020
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2020-35276?

CVE-2020-35276 is a vulnerability in EgavilanMedia ECM Address Book 1.0 that allows an attacker to bypass the Admin Login panel through SQL injection and gain Admin access.

2

How severe is CVE-2020-35276?

CVE-2020-35276 has a severity rating of 9.8 (Critical).

3

How does CVE-2020-35276 affect EgavilanMedia ECM Address Book 1.0?

CVE-2020-35276 affects EgavilanMedia ECM Address Book 1.0 by allowing an attacker to perform SQL injection, bypass the Admin Login panel, and gain Admin access.

4

What is the CWE ID associated with CVE-2020-35276?

CVE-2020-35276 is associated with CWE ID 89 (SQL Injection).

5

How can I mitigate CVE-2020-35276 in EgavilanMedia ECM Address Book 1.0?

To mitigate CVE-2020-35276 in EgavilanMedia ECM Address Book 1.0, it is recommended to apply the latest security updates or patches provided by the vendor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203