CVE-2021-36807: SQL Injection
Published Nov 26, 2021
·Updated
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
Affected Software
1 affected component
Sophos Unified Threat Management Up2date<9.708
Event History
Nov 26, 2021
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36807.
2
What is the severity of CVE-2021-36807?
The severity of CVE-2021-36807 is high, with a CVSS score of 8.8.
3
How does CVE-2021-36807 affect the software?
CVE-2021-36807 affects the user portal of SG UTM before version 9.708 MR8.
4
How can an authenticated user exploit CVE-2021-36807?
An authenticated user can potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
5
How can I fix CVE-2021-36807?
To fix CVE-2021-36807, it is recommended to update SG UTM to version 9.708 MR8 or later.