---
id: CVE-2020-35273
title: >-
  EgavilanMedia User Registration & Login System with Admin Panel 1.0 is
  affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in
  the User Profile panel
summary: >-
  EgavilanMedia User Registration & Login System with Admin Panel 1.0 is
  affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in
  the User Profile panel. An attacker can update any user's account.
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
vendor: egavilanmedia
product: user_registration_&_login_system_with_admin_panel
affected:
  - user_registration_&_login_system_with_admin_panel = 1.0
published: '2020-12-21'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-35273'
references:
  - url: 'https://www.exploit-db.com/exploits/49151'
    label: cve@mitre.org
  - url: 'http://egavilanmedia.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/49151'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00569
epssPercentile: 0.4473
ingestedAt: '2026-07-05T00:59:25.579Z'
---

## Overview

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

## Affected

- `user_registration_&_login_system_with_admin_panel = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
