CVE-2020-36542
Dashboard / Vulnerabilities / CVE-2020-36542
CVE-2020-36542
Published: 7 Jun 2022Last Modified: 8 Jul 2026
Summary:
Details: A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
References: https://vuldb.com/?id.159435, https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian, https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
version_3.0.3
version_3.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
