First published: Wed Apr 14 2021(Updated: )
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Devolutions Devolutions Server | <2020.3.18 | |
Devolutions Devolutions Server | <2021.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28157 is an SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18.
CVE-2021-28157 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
CVE-2021-28157 has a severity rating of 7.2 (high).
Devolutions Server versions before 2021.1 and Devolutions Server LTS before 2020.3.18 are affected by CVE-2021-28157.
To fix CVE-2021-28157, update Devolutions Server to version 2021.1 or apply the patch for Devolutions Server LTS version 2020.3.18.