Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Naviwebs
Naviwebs navigate Cms |
|
| Vendors & Products |
Naviwebs
Naviwebs navigate Cms |
Mon, 02 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts. | |
| Title | Navigate CMS 2.8.7 - ''sidx' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-30T22:07:19.052Z
Updated: 2026-02-02T20:06:13.908Z
Reserved: 2026-01-28T18:18:30.525Z
Link: CVE-2020-37053
Updated: 2026-02-02T20:06:10.335Z
Status : Undergoing Analysis
Published: 2026-01-30T23:16:11.300
Modified: 2026-02-03T16:44:36.630
Link: CVE-2020-37053
No data.