Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-448 |
|
History
Tue, 21 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortisoar |
|
| CPEs | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisoar |
Status: PUBLISHED
Assigner: fortinet
Published: 2024-06-11T14:32:00.651Z
Updated: 2024-08-02T10:42:26.252Z
Reserved: 2023-01-18T08:30:21.306Z
Link: CVE-2023-23775
Updated: 2024-08-02T10:42:26.252Z
Status : Analyzed
Published: 2024-06-11T15:15:53.723
Modified: 2025-01-21T21:56:39.483
Link: CVE-2023-23775
No data.