CVE-2020-35737
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 10%
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/49378unverifiedcve_referencepacketstormsecurity.com/files/160826/Newgen-Correspondence-Management-System-eGov-12.0-Insecure-Direct-Object-Reference.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.