CVE-2020-36125

HIGH

Pax Technology PAXSTORE < 7.0.8_20200511171508 - Authenticated Incorrect Access Control via Direct Endpoint Request

Title source: llm
STIX 2.1

Description

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.

References (3)

Core 3
Core References
Product x_refsource_misc
https://www.whatspos.com/
Exploit, Third Party Advisory x_refsource_misc
https://blog.pridesec.com.br/p/4c972078-5f01-419e-8bea-cf31ff2e3670/

Scores

CVSS v3 7.1
EPSS 0.0094
EPSS Percentile 56.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-306
Status published
Products (1)
paxtechnology/paxstore < 7.0.8_20200511171508
Published May 07, 2021
Tracked Since Feb 18, 2026