CVE-2020-37053

HIGH

Navigate CMS 2.8.7 - Authenticated SQL Injection

Title source: llm

Description

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.

Exploits (1)

exploitdb WORKING POC
by Gus Ralph · pythonwebappsphp
https://www.exploit-db.com/exploits/48545

Scores

CVSS v3 7.1
EPSS 0.0001
EPSS Percentile 2.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
naviwebs/navigate_cms 2.8.7
Published Jan 30, 2026
Tracked Since Feb 18, 2026