Description
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007
Scores
CVSS v3
9.8
EPSS
0.0095
EPSS Percentile
76.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (3)
sonicwall/analytics
< 2.5.0.3-2520
sonicwall/global_management_system
9.3.1
sonicwall/global_management_system
< 9.3.1
Published
Jul 29, 2022
Tracked Since
Feb 18, 2026