PT-2020-17308 · Egavilanmedia · Egavilanmedia Ecm Address Book
Published
2020-12-21
·
Updated
2021-12-22
·
CVE-2020-35276
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EgavilanMedia ECM Address Book version 1.0
Description
The issue allows an attacker to bypass the Admin Login panel through SQL injection, gaining Admin access and the ability to add or remove any user. This can potentially lead to unauthorized access to sensitive information, such as confidential patient data.
Recommendations
For EgavilanMedia ECM Address Book version 1.0, consider temporarily restricting access to the Admin Login panel until a patch is available. As a mitigation measure, avoid using the vulnerable login functionality and limit user management capabilities to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Egavilanmedia Ecm Address Book