Start your free trial today.
Protect your organization with cutting-edge cybersecurity solutions designed for resilience and efficiency. Secure your digital assets with confidence.
Your Shield Against Threats
Unleash the Power of Cybersecurity
Boost Your Security, Enhance Your Business
We solve Your Cyber Challenges
Quick Links
Resources
Deepaegis Portals
2025 Deepaegis. All Rights Reserved.
Multiple authenticated SQL injection vulnerabilities were discovered in UISP Application version 2.4.206 and earlier. These vulnerabilities allow a malicious user with low privileges to escalate privileges and potentially execute unauthorized queries, leading to full system compromise.
Successful exploitation may allow attackers to: Escalate privileges to admin level Read/write sensitive database content Disrupt application availability
UISP Application
Affected Version: 2.4
A fixed version is available via Ubiquiti’s official update channels.
Restrict access to low-privileged accounts until patching
Apply latest updates from Ubiquiti Monitor user actions on the platform Use Web Application Firewalls (WAF) to prevent SQL payloads
Analyze logs for abnormal SQL queries from authenticated users Use SQLi scanning tools on authenticated sessions
Not specified
Not specified
No references provided
No affected organizations specified
This document contains sensitive information. Unauthorized distribution is prohibited.