Description
A boolean-based blind SQL injection vulnerability exists in the web user interface of Kerio Control firewall. The vulnerability allows authenticated attackers to extract sensitive data from the underlying database.
Impact
An attacker with valid administrator credentials can extract sensitive information from the firewall's database, including user credentials, configuration data, and VPN settings.
Solution
Upgrade to Kerio Control 8.4.0 or later.