#VU24917 Improper access control in eG Manager - CVE-2020-8591
Published: February 4, 2020
eG Manager
eG Innovations, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions via a "com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r" request, gain unauthorized access to the application and execute arbitrary code on the target system.