CVE-2020-5511 describes an authentication bypass vulnerability in PHPGurukul Small CRM v2.0, specifically impacting the administrator login page. This flaw, categorized as a SQL injection (CWE-89), allows an attacker to gain unauthorized access. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity, network-based vector, and high potential for confidentiality, integrity, and availability compromise. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) have been identified, and community discussion is minimal, the high FAUCET Risk Score of 70/100 indicates its inherent danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:small_crm_project:small_crm:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.