WebEOC prior to 6.0.2 does not properly check user authorization, which allows remote malicious users to gain privileges via a direct request to a resource.
esi products webeoc