A post-auth read-only SQL injection vulnerability allows...
Low severity
Unreviewed
Published
Dec 1, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Dec 1, 2022
Published to the GitHub Advisory Database
Dec 1, 2022
Last updated
Jan 31, 2023
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall older than version 19.5 GA.
References