{"id":"CVE-2020-29574","details":"An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.","modified":"2026-03-14T10:07:17.203420Z","published":"2020-12-11T17:15:13.480Z","references":[{"type":"WEB","url":"https://www.cyberoam.com/ngfw.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29574"},{"type":"ADVISORY","url":"https://www.bleepingcomputer.com/news/security/sophos-fixes-sql-injection-vulnerability-in-their-cyberoam-os/"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2020-12-04"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29574.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}