Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
2022-07-18T18:15:09.120
2024-11-21T06:53:28.307
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiadc | < 6.2.3 | Yes |
Application | fortinet | fortiadc | 7.0.0 | Yes |
Application | fortinet | fortiadc | 7.0.1 | Yes |