ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36969”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36969
Published
2026-01-28
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.