Description
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
Related CPE's
a
devolutions
devolutions_server
2
References
https://devolutions.net/security/advisories/DEVO-2021-0004
Third Party Advisory
https://devolutions.net/security/advisories/DEVO-2021-0004
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
7.2 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-14T18:15:11.410Z
4 years agoLast modified
2024-11-21T04:59:12.440Z
1 year ago