---
id: CVE-2020-35276
title: EgavilanMedia ECM Address Book 1.0 is affected by SQL injection
summary: >-
  EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker
  can bypass the Admin Login panel through SQLi and get Admin access and add or
  remove any user.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: egavilanmedia
product: ecm_address_book
affected:
  - ecm_address_book = 1.0
published: '2020-12-21'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-35276'
references:
  - url: 'http://ecm.com'
    label: cve@mitre.org
  - url: >-
      https://hardik-solanki.medium.com/authentication-admin-panel-bypass-which-leads-to-full-admin-access-control-c10ec4ab4255
    label: cve@mitre.org
  - url: 'http://ecm.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://egavilanmedia.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://hardik-solanki.medium.com/authentication-admin-panel-bypass-which-leads-to-full-admin-access-control-c10ec4ab4255
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01563
epssPercentile: 0.74204
ingestedAt: '2026-07-05T00:59:25.588Z'
---

## Overview

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

## Affected

- `ecm_address_book = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
