CVE-2020-37135
HIGHAMSS++ 4.7 - Authentication Bypass via Hardcoded Credentials
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37135. PoCs published by indoushka.
AI-analyzed exploit summary This exploit reveals a backdoor admin account in AMSS++ 4.7, allowing unauthorized access using the credentials 'admin' and '1234'. The PoC is trivial and relies on default credentials left in the software.
Description
AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.
Exploits (1)
This exploit reveals a backdoor admin account in AMSS++ 4.7, allowing unauthorized access using the credentials 'admin' and '1234'. The PoC is trivial and relies on default credentials left in the software.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N