CVE-2021-38167
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to by
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
CRITICAL · CVSS 9.8
EPSS 0.00845
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0