CVE detail
CVE-2020-26805 — CVE-2020-26805
Published 2020-11-12 · Modified 2026-06-17 · Vendor sapplica · Product sentrifugo · Source nvd
HIGH
severity
CVSS-derived band
0.0150
EPSS probability
exploitation probability, 30d
72.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability. Attacker can inject SQL commands into query, read data from database or write data into the database.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References