CyberRota
Back to database

CVE-2020-37242

HIGH · CVSS 8.2 EPSS 0.09% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-16 · Last synced: 2026-06-09

CyberRota Analysis

SQL Injection riski içeriyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-37242
Severity
HIGH
CVSS
8.2
EPSS
0.09%

Original NVD Description

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information.