CVE-2021-36807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
26/11/2021
Last modified:
30/11/2021

Description

An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:unified_threat_management_up2date:*:*:*:*:*:*:*:* 9.708 (excluding)