Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through multiple function calls and ultimately interpolated into a SQL query string using Python string formatting, allowing attackers to execute arbitrary SQL commands. Version 8.2.6.4 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Roxy-wi
Roxy-wi roxy-wi |
|
| CPEs | cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roxy-wi
Roxy-wi roxy-wi |
|
| Metrics |
cvssV3_1
|
Fri, 24 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through multiple function calls and ultimately interpolated into a SQL query string using Python string formatting, allowing attackers to execute arbitrary SQL commands. Version 8.2.6.4 fixes the issue. | |
| Title | Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-24T02:05:02.737Z
Updated: 2026-04-24T12:10:25.193Z
Reserved: 2026-03-17T19:27:06.345Z
Link: CVE-2026-33078
Updated: 2026-04-24T12:10:08.223Z
Status : Analyzed
Published: 2026-04-24T03:16:10.657
Modified: 2026-04-27T15:10:14.757
Link: CVE-2026-33078
No data.
ReportizFlow