elaniin CMS 1.0 - Authentication Bypass
Vulnerability Description
Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36999
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- BKpatron
Affected Vendor
Elaniin
View all reports →