A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
2022-12-01T18:15:10.503
2025-04-23T16:15:24.810
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sophos | xg_firewall_firmware | ≤ 19.0 | Yes |
Hardware | sophos | xg_firewall | - | No |