CVE-2021-28157
14.04.2021, 20:15
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2020.3.18 |
| devolutions | devolutions_server | 𝑥 < 2021.1 |
𝑥
= Vulnerable software versions