CVE-2020-36125: Paxtechnology Paxstore
High severity, CVSS 7.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.
Affected products
- Paxtechnology Paxstore: up to and including 7.0.8_20200511171508
Published 2021-05-07. Last modified 2026-06-17.