CVE-2020-8510

CRITICAL

phpABook 0.9 Intermediate - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-8510. PoCs published by 0xEmma.

AI-analyzed exploit summary The repository describes an authentication bypass vulnerability in phpABook 0.9i, where setting a specific cookie allows unauthorized admin access. The technical details include the cookie format and its exploitation mechanism.

Description

An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

Exploits (1)

github WRITEUP 4 stars
by 0xEmma · poc
https://github.com/0xEmma/CVEs/tree/master/CVEs/2020-01-31-phpABook-Auth-Bypass-CVE-2020-8510.md

The repository describes an authentication bypass vulnerability in phpABook 0.9i, where setting a specific cookie allows unauthorized admin access. The technical details include the cookie format and its exploitation mechanism.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: phpABook 0.9i
No auth needed
Prerequisites: ability to set browser cookies
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://sourceforge.net/p/phpabook/news/
Third Party Advisory x_refsource_misc
https://0xem.ma/cve/2020/01/31/CVE-2020-8510.html

Scores

CVSS v3 9.8
EPSS 0.0125
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
phpabook_project/phpabook 0.9
Published Feb 03, 2020
Tracked Since Feb 18, 2026