CVE-2020-37154
7.1
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploading backdoor files to the web application directory.
References (4)
Source: disclosure@vulncheck.com
Source: disclosure@vulncheck.com
Source: disclosure@vulncheck.com
Source: disclosure@vulncheck.com
Timeline (8)
2/7/20268 changes
New CVE Received - Reference
12:15 AM
- -
+ https://www.vulncheck.com/advisories/election-id-sql-injection
New CVE Received - Reference
12:15 AM
- -
+ https://www.exploit-db.com/exploits/48122
New CVE Received - Reference
12:15 AM
- -
+ https://sourceforge.net/projects/election-by-tripath/
New CVE Received - Reference
12:15 AM
- -
+ https://github.com/J3rryBl4nks/eLection-TriPath-/blob/master/SQLiIntoRCE.md
New CVE Received - CWE
12:15 AM
- -
+ CWE-89
New CVE Received - CVSS V3.1
12:15 AM
- -
+ AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
New CVE Received - CVSS V4.0
12:15 AM
- -
+ AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
New CVE Received - Description
12:15 AM
- -
+ eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploading backdoor files to the web application directory.