Presentation

A user with permissions to access the lilac export can inject SHELL commands resulting in an authenticated remote shell. We can then obtain a shell in ROOT.

Exploit

We have no knowledge of an exploit today.

Impacted Version(s)

EON 4.2+ EON 5.0+

Fixed Version(s)

EON 5.3-11

Fix

Download latest EON fixed version.