CVE-2021-38167: SQL Injection
Published Aug 7, 2021
·Updated
Roxy-WI through 5.2.2.0 allows SQL Injection via checklogin. An unauthenticated attacker can extract a valid uuid to bypass authentication.
Affected Software
1 affected component
Roxy-WI Roxy-wi<=5.2.2.0
Event History
Aug 7, 2021
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38167?
CVE-2021-38167 has been assigned a medium severity rating due to its potential for unauthorized access via SQL injection.
2
How do I fix CVE-2021-38167?
To fix CVE-2021-38167, upgrade Roxy-WI to version 5.2.2.1 or later, where the vulnerability is resolved.
3
Who is affected by CVE-2021-38167?
CVE-2021-38167 affects all versions of Roxy-WI up to and including 5.2.2.0.
4
What type of vulnerability is CVE-2021-38167?
CVE-2021-38167 is a SQL injection vulnerability that allows attackers to bypass authentication.
5
Can an attacker exploit CVE-2021-38167 without authentication?
Yes, an unauthenticated attacker can exploit CVE-2021-38167 to extract valid UUIDs and bypass authentication.