Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vpp-5ch5-wr42

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

EPSS

Процентиль: 99%
0.77688
Высокий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

EPSS

Процентиль: 99%
0.77688
Высокий

Дефекты

CWE-89