CVE-2021-28157: SQL Injection
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28157?
CVE-2021-28157 is an SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18.
How does CVE-2021-28157 impact Devolutions Server?
CVE-2021-28157 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
How severe is CVE-2021-28157?
CVE-2021-28157 has a severity rating of 7.2 (high).
Which versions of Devolutions Server are affected by CVE-2021-28157?
Devolutions Server versions before 2021.1 and Devolutions Server LTS before 2020.3.18 are affected by CVE-2021-28157.
How can I fix CVE-2021-28157?
To fix CVE-2021-28157, update Devolutions Server to version 2021.1 or apply the patch for Devolutions Server LTS version 2020.3.18.