CVE-2020-37156: Diveshlunker Bloodx

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access.

Affected products

Published 2026-02-11. Last modified 2026-06-17.