PT-2026-5490 · Unknown · Navigate Cms

Gus Ralph

·

Publicado

2026-01-30

·

Atualizado

2026-01-31

·

CVE-2020-37053

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Navigate CMS version 2.8.7
Description Navigate CMS 2.8.7 contains an authenticated SQL injection issue that allows attackers to obtain database information by manipulating the sidx parameter within comments. Attackers can exploit this to extract user activation keys using time-based blind SQL injection techniques, potentially allowing for password resets of administrative accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-37053

Produtos afetados

Navigate Cms