CyberRota Analysis
AI-GeneratedAn authenticated SQL injection vulnerability in the scheduled report feature of WatchGuard Dimension allows users with report administration permissions to execute arbitrary commands as the Dimension WebUI process user. This high-severity flaw could lead to significant security breaches, including unauthorized access to sensitive data and system control. Organizations using WatchGuard Dimension should prioritize patching this vulnerability to mitigate potential exploitation risks.
Original NVD Description
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.