PT-2026-7670 · Diveshlunker · Bloodx

Riamloo

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2020-37156

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BloodX version 1.0
Description An authentication bypass exists in the 'login.php' endpoint. Attackers can gain unauthorized access to the dashboard without valid credentials by sending a crafted payload using the =''or parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2020-37156

Affected Products

Bloodx