An SQL Injection issue in Devolutions Server prior to 2021.1 and Devolutions Server LTS prior to 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
devolutions devolutions server |