SQL Injection Vulnerabilities in Dell SonicWall Scrutinizer
CVE-2014-4977

Currently unrated

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
16 July 2014

Summary

Dell SonicWall Scrutinizer version 11.0.1 is susceptible to multiple SQL injection vulnerabilities that allow remote authenticated users to execute arbitrary SQL commands. Attackers can exploit the flaws by manipulating parameters such as selectedUserGroup in create new user requests or user_id and methodDetail in specific functions. This could enable unauthorized access to sensitive data and system functions, posing significant risks to data integrity and confidentiality.

References

EPSS Score

84% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.