Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
References
Link | Resource |
---|---|
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-18-5-4 | Vendor Advisory |
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-19-0-1 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Sophos
Published: 2022-09-07T18:00:14
Updated: 2022-09-07T18:00:14
Reserved: 2022-05-20T00:00:00
Link: CVE-2022-1807
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-09-07T18:15:08.647
Modified: 2022-09-12T18:38:29.497
Link: CVE-2022-1807
JSON object: View
Redhat Information
No data.
CWE