ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36913”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36913
Published
2026-01-06
CVSS:
8.5
ShadowTrackr CVSS:
6.0
Summary:
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.