CVE-2019-7478: SQL Injection
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7478?
CVE-2019-7478 is a vulnerability that allows an unauthenticated user to perform SQL injection in the Webservice module of SonicWALL Global Management System (GMS) versions 8.4, 8.5, 8.6, 8.7, 9.0, and 9.1.
What is the severity of CVE-2019-7478?
CVE-2019-7478 has a severity rating of 9.8 (Critical).
Which versions of SonicWALL Global Management System (GMS) are affected by CVE-2019-7478?
CVE-2019-7478 affects GMS versions 8.4, 8.5, 8.6, 8.7, 9.0, and 9.1.
How can an unauthenticated user exploit CVE-2019-7478?
An unauthenticated user can exploit CVE-2019-7478 by performing SQL injection in the Webservice module of SonicWALL Global Management System (GMS).
Is there a fix available for CVE-2019-7478?
Yes, SonicWALL has provided a fix for CVE-2019-7478. It is recommended to update to the latest version of SonicWALL Global Management System (GMS) to mitigate this vulnerability.