Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8656

Опубликовано: 07 фев. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eyesofnetwork:eyesofnetwork:5.3-0:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.77688
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

EPSS

Процентиль: 99%
0.77688
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89