CVE-2022-3710
01.12.2022, 18:15
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
Vendor | Product | Version |
---|---|---|
sophos | xg_firewall_firmware | 𝑥 < 19.5 |
𝑥
= Vulnerable software versions