CVE-2024-12729

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
Configurations

No configuration.

History

19 Dec 2024, 22:15

Type Values Removed Values Added
Summary (en) A post-auth SQLi vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1). (en) A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
CWE CWE-94

19 Dec 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 21:15

Updated : 2024-12-19 22:15


NVD link : CVE-2024-12729

Mitre link : CVE-2024-12729

CVE.ORG link : CVE-2024-12729


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')