Authenticated Inline-Query SQL Injection Vulnerability in Untangle NG Firewall 14.2.0

Authenticated Inline-Query SQL Injection Vulnerability in Untangle NG Firewall 14.2.0

CVE-2019-18646 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.