An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/EyesOfNetworkCommunity/eonweb/issues/120 | issue tracking |
https://github.com/Orange-Cyberdefense/CVE-repository/ | third party advisory |