CVE-2020-37008

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) EasyPMS 1.0.0 contiene una vulnerabilidad de omisión de autenticación que permite a usuarios sin privilegios manipular consultas SQL en solicitudes JSON para acceder a información de usuario administrador. Los atacantes pueden explotar una validación de entrada débil inyectando comillas simples en parámetros de ID y modificar contraseñas de usuario administrador sin una autenticación de token adecuada.

29 Jan 2026, 17:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/48858 - () https://www.exploit-db.com/exploits/48858 -

29 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 15:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-37008

Mitre link : CVE-2020-37008

CVE.ORG link : CVE-2020-37008


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key