CVE-2020-35276: Egavilanmedia Ecm Address Book

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

Affected products

Published 2020-12-21. Last modified 2026-07-09.