WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Webeoc | Esi_products | * | 6.0.1 (including) |
References