CVE-2020-37135

HIGH

AMSS++ 4.7 - Auth Bypass

Title source: llm
STIX 2.1

Description

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

Exploits (1)

exploitdb WORKING POC
by indoushka · textwebappsphp
https://www.exploit-db.com/exploits/48114

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 9.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
Amssplus/AMSS++ 4.7
Published Feb 07, 2026
Tracked Since Feb 18, 2026