nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37008 CVE-2020-37008
HIGH
EasyPMS 1.0.0 - Authentication Bypass
Record summary
CVE-2020-37008 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EasyPMSBrowse Elektraweb / EasyPMS | CVE List | 1.0.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBEasyPMS 1.0.0 - Authentication BypassExploitDB exploitby Jok3rNot analyzed1 file
References
4Vendor Homepageproduct
https://www.elektraweb.com/en ExploitDB-48858exploit
https://www.exploit-db.com/exploits/48858 VulnCheck Advisory: EasyPMS 1.0.0 - Authentication BypassThird-party advisory
https://www.vulncheck.com/advisories/easypms-authentication-bypass