First published: Sat Aug 07 2021(Updated: )
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Roxy-wi | <=5.2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38167 has been assigned a medium severity rating due to its potential for unauthorized access via SQL injection.
To fix CVE-2021-38167, upgrade Roxy-WI to version 5.2.2.1 or later, where the vulnerability is resolved.
CVE-2021-38167 affects all versions of Roxy-WI up to and including 5.2.2.0.
CVE-2021-38167 is a SQL injection vulnerability that allows attackers to bypass authentication.
Yes, an unauthenticated attacker can exploit CVE-2021-38167 to extract valid UUIDs and bypass authentication.