CVE-2020-35276
Critical · CVSS 9.8EgavilanMedia ECM Address Book — SQL Injection Authentication Bypass
- CVSS
- 9.8
- nvd
- EPSS
- 1.76%
- 75th pct
- KEV
- No
- Class
- other
- CWE-89
Description
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Search profile — drives PoC discovery
Symbols Admin LoginECM Address Bookadmin panelSQLi bypassegavilanmedia
Keywords CVE-2020-35276EgavilanMediaECM Address BookSQL injectionadmin login bypassauthentication bypassSQLiCWE-89
Versions: 1.0
Ranked PoCs (6) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 12AdityaBhatt3010/Bypassing-Login-via-NoSQL-Operator-Injection-A-MongoDB-Authentication-Hack needs reviewrecent activitygh_search
- ★ 5recent activitygh_search
- ★ 2recent activitygh_search · Shell
- ★ 1Ko-kn3t/CVE-2020-25273 needs reviewgh_search
- ★ 1
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z