packetstormsecurity.com
http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.html CVE-2020-35737
HIGH
Newgen Correspondence Management System (corms) eGov 12.0 - IDOR
Record summary
CVE-2020-35737 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNewgen Correspondence Management System (corms) eGov 12.0 - IDORExploitDB exploitby ALI AL SINANNot analyzed1 file
References
4gist.github.com
https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35737 exploit-db.com
https://www.exploit-db.com/exploits/49378