ZeroHour

CVE-2020-8656

PoC ×2
CVSS 3.1
9.8 critical
EPSS
85%p100
Published
()
Modified
Description

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

Vendors
eyesofnetwork
Products
eyesofnetwork
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.