CVE-2020-35276: SQL Injection
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EgavilanMedia ECM Address Bookto a version that resolves this vulnerability.Fixed in 1.0
Event History
Frequently Asked Questions
What is CVE-2020-35276?
CVE-2020-35276 is a vulnerability in EgavilanMedia ECM Address Book 1.0 that allows an attacker to bypass the Admin Login panel through SQL injection and gain Admin access.
How severe is CVE-2020-35276?
CVE-2020-35276 has a severity rating of 9.8 (Critical).
How does CVE-2020-35276 affect EgavilanMedia ECM Address Book 1.0?
CVE-2020-35276 affects EgavilanMedia ECM Address Book 1.0 by allowing an attacker to perform SQL injection, bypass the Admin Login panel, and gain Admin access.
What is the CWE ID associated with CVE-2020-35276?
CVE-2020-35276 is associated with CWE ID 89 (SQL Injection).
How can I mitigate CVE-2020-35276 in EgavilanMedia ECM Address Book 1.0?
To mitigate CVE-2020-35276 in EgavilanMedia ECM Address Book 1.0, it is recommended to apply the latest security updates or patches provided by the vendor.