PT-2019-9220 · Sophos · Sophos Firewall

Publicado

2019-06-20

·

Atualizado

2019-06-24

·

CVE-2018-16116

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos XG firewall version 17.0.8 MR-8
Description The issue allows remote authenticated attackers to execute arbitrary SQL commands. This is achieved via the username GET parameter in the AccountStatus.jsp file of the Admin Portal.
Recommendations For Sophos XG firewall version 17.0.8 MR-8, consider restricting access to the AccountStatus.jsp file until a patch is available. As a temporary workaround, avoid using the username parameter in the affected API endpoint.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16116

Produtos afetados

Sophos Firewall