๐Ÿ” CVE Alert

CVE-2020-37008

HIGH 7.5

EasyPMS 1.0.0 - Authentication Bypass

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
27th

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

CWE CWE-639
Vendor elektraweb
Product easypms
Published Jan 29, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for elektraweb easypms

Be the first to know when new high vulnerabilities affecting elektraweb easypms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Elektraweb / EasyPMS
1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/48858 elektraweb.com: https://www.elektraweb.com/en/ vulncheck.com: https://www.vulncheck.com/advisories/easypms-authentication-bypass

Credits

Jok3r