Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.
History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Naviwebs
Naviwebs navigate Cms
Vendors & Products Naviwebs
Naviwebs navigate Cms

Mon, 02 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 22:30:00 +0000

Type Values Removed Values Added
Description Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.
Title Navigate CMS 2.8.7 - ''sidx' SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-30T22:07:19.052Z

Updated: 2026-02-02T20:06:13.908Z

Reserved: 2026-01-28T18:18:30.525Z

Link: CVE-2020-37053

cve-icon Vulnrichment

Updated: 2026-02-02T20:06:10.335Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-01-30T23:16:11.300

Modified: 2026-02-03T16:44:36.630

Link: CVE-2020-37053

cve-icon Redhat

No data.