CVE-2020-37008
EasyPMS 1.0.0 - Authentication Bypass
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
27th
EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.
| CWE | CWE-639 |
| Vendor | elektraweb |
| Product | easypms |
| Published | Jan 29, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for elektraweb easypms
Be the first to know when new high vulnerabilities affecting elektraweb easypms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Elektraweb / EasyPMS
1.0.0
References
Credits
Jok3r