Executive brief
EyesOfNetwork 5.3 uses a hard-coded API key (EONAPI_KEY) by default in include/api_functions.php. This allows remote attackers to calculate or guess the administrative access token, leading to unauthorized administrative access.
Affected products
- EyesOfNetwork EyesOfNetwork 5.3
- EyesOfNetwork eonweb 5.3
Timeline
- 2020-02-06: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-03: patched: CISA due date for applying updates