WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Webeoc |
Esi_products |
* |
6.0.1 (including) |
References