Total vulnerabilities in the database
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
CVSS v2:
No CWE or OWASP classifications available.