Medium severity5.3NVD Advisory· Published Jan 6, 2026· Updated Apr 15, 2026
CVE-2020-36913
CVE-2020-36913
Description
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- exchange.xforce.ibmcloud.com/vulnerabilities/186246nvd
- packetstorm.news/files/id/158703nvd
- packetstormsecurity.com/files/158703nvd
- www.enlogic-show.com/index.dhtml/23695c31af422b939dd049908/-/deDE/-/CS/-/support/changelognvd
- www.vulncheck.com/advisories/all-dynamics-software-enlogicshow-session-fixation-authentication-bypassnvd
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5577.phpnvd
News mentions
0No linked articles in our index yet.