Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
References
Link Resource
https://github.com/hap-wi/roxy-wi/issues/285 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-07T18:00:36

Updated: 2021-08-07T18:00:36

Reserved: 2021-08-07T00:00:00


Link: CVE-2021-38167

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-08-07T18:15:07.080

Modified: 2021-08-13T17:02:02.987


Link: CVE-2021-38167

JSON object: View

cve-icon Redhat Information

No data.

CWE