Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38167.json"