A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-465 |
|
History
Mon, 03 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiweb |
|
| CPEs | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortiweb |
Tue, 14 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published: 2025-01-14T14:08:36.557Z
Updated: 2025-01-14T20:56:58.704Z
Reserved: 2024-12-09T11:19:49.470Z
Link: CVE-2024-55593
Updated: 2025-01-14T15:15:31.810Z
Status : Analyzed
Published: 2025-01-14T14:15:34.610
Modified: 2025-02-03T22:06:19.163
Link: CVE-2024-55593
No data.