CVE-2020-35737

I

n Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

Configurations

Configuration 1 (hide)

cpe:2.3:a:newgensoft:egov:12.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:27

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.html - Exploit, Third Party Advisory, VDB Entry
References () https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486 - Third Party Advisory () https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486 - Third Party Advisory
References () https://www.exploit-db.com/exploits/49378 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/49378 - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2020-12-30 20:15

Updated : 2024-11-21 05:27


NVD link : CVE-2020-35737

Mitre link : CVE-2020-35737

CVE.ORG link : CVE-2020-35737


JSON object : View

Products Affected