VulnerabilityModified
CVE-2020-35737
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
HIGH 7.5EPSS 10.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 10.31% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- newgensoft/egov
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.htmlExploit, Third Party Advisory, VDB Entry
- https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486Third Party Advisory
- https://www.exploit-db.com/exploits/49378Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.htmlExploit, Third Party Advisory, VDB Entry
- https://gist.github.com/AliAlsinan/0323e57d2345ef0b4e73c803dba93486Third Party Advisory
- https://www.exploit-db.com/exploits/49378Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.