High severity7.2NVD Advisory· Published Sep 7, 2022· Updated Jun 17, 2026
CVE-2022-1807
CVE-2022-1807
Description
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:sophos:firewall:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:sophos:firewall:*:*:*:*:*:*:*:*range: <18.5
- cpe:2.3:o:sophos:firewall:18.5:-:*:*:*:*:*:*
- cpe:2.3:o:sophos:firewall:18.5:mr1-1:*:*:*:*:*:*
- cpe:2.3:o:sophos:firewall:18.5:mr1:*:*:*:*:*:*
- cpe:2.3:o:sophos:firewall:18.5:mr2:*:*:*:*:*:*
- cpe:2.3:o:sophos:firewall:18.5:mr3:*:*:*:*:*:*
- cpe:2.3:o:sophos:firewall:19.0:-:*:*:*:*:*:*
- Range: <18.5 MR4 and <19.0 MR1
- Range: unspecified
Patches
Vulnerability mechanics
References
2- www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-18-5-4nvdVendor Advisory
- www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-19-0-1nvdVendor Advisory
News mentions
0No linked articles in our index yet.