Vulnerability CVE-2020-35737


Published: 2020-12-30

Description:
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Newgen Correspondence Management System eGov 12.0 Insecure Direct Object Reference
Ali Al Sinan
07.01.2021

Type:

NVD-CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Newgensoft -> EGOV 

 References:
http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.html
https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486
https://www.exploit-db.com/exploits/49378

Copyright 2024, cxsecurity.com

 

Back to Top