CVE Vulnerabilities

CVE-2020-37156

Authentication Bypass Using an Alternate Path or Channel

Published: Feb 11, 2026 | Modified: Feb 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with =or parameters to bypass login authentication and gain unauthorized access.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References