nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37053 CVE-2020-37053
HIGH
Navigate CMS 2.8.7 - ''sidx' SQL Injection
Record summary
CVE-2020-37053 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Navigate CMSBrowse Naviwebs S.C. / Navigate CMS | CVE List | 2.8.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNavigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)ExploitDB exploitby Gus RalphNot analyzed1 file
References
5Navigate CMS SourceForge Pageproduct
https://sourceforge.net/projects/navigatecms ExploitDB-48545exploit
https://www.exploit-db.com/exploits/48545 Navigate CMS Official Homepageproduct
https://www.navigatecms.com/en/home VulnCheck Advisory: Navigate CMS 2.8.7 - ''sidx' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/navigate-cms-sidx-sql-injection