An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.
2025-03-14T16:15:27.027
2025-07-24T20:01:42.143
Analyzed
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | ≤ 6.2.7 | Yes |
Application | fortinet | fortiweb | ≤ 6.3.18 | Yes |
Application | fortinet | fortiweb | ≤ 6.4.2 | Yes |
Application | fortinet | fortiweb | < 7.0.2 | Yes |