First published: Fri Nov 26 2021(Updated: )
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Unified Threat Management Up2date | <9.708 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36807.
The severity of CVE-2021-36807 is high, with a CVSS score of 8.8.
CVE-2021-36807 affects the user portal of SG UTM before version 9.708 MR8.
An authenticated user can potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
To fix CVE-2021-36807, it is recommended to update SG UTM to version 9.708 MR8 or later.