Record summary

CVE-2020-35737 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNewgen Correspondence Management System (corms) eGov 12.0 - IDORExploitDB exploitby ALI AL SINANNot analyzed1 file
ExploitDB

PoC details

References

4