peter bassill · operator
$ cve CVE-2020-8656 JSON

CVE-2020-8656 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 84.6% (pctl 100)

Patch early

A public exploit exists.

Description

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS84.6% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2020-02-07
Last modified2026-06-17

Affected (1)

VendorProduct
eyesofnetworkeyesofnetwork

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD