CVE-2020-37008

HIGH

EasyPMS 1.0.0 - Unauthenticated Authorization Bypass via SQL Query Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37008. PoCs published by Jok3r.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in EasyPMS 1.0.0 via SQL injection in a JSON request, allowing a low-privilege user to escalate to HotelOwner admin by manipulating the 'ID' column and resetting the admin password.

Description

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

Exploits (1)

exploitdb WORKING POC
by Jok3r · textwebappsjson
https://www.exploit-db.com/exploits/48858

This exploit demonstrates an authentication bypass vulnerability in EasyPMS 1.0.0 via SQL injection in a JSON request, allowing a low-privilege user to escalate to HotelOwner admin by manipulating the 'ID' column and resetting the admin password.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: EasyPMS 1.0.0
Auth required
Prerequisites: Valid low-privilege user credentials · Access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48858
Various Sources product
https://www.elektraweb.com/en/
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/easypms-authentication-bypass

Scores

CVSS v3 7.5
EPSS 0.0046
EPSS Percentile 36.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
Elektraweb/EasyPMS 1.0.0
Published Jan 29, 2026
Tracked Since Feb 18, 2026