7.5
CVSSv3

CVE-2020-35737

Published: 30/12/2020 Updated: 24/02/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

newgensoft egov 12.0

Exploits

Newgen Correspondence Management System (corms) eGov version 120 suffers from an insecure direct object reference vulnerability ...