Home
MEDIUM: 4.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:XDefault status
unaffected
7.4.0 (semver)
affected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
6.4.4 (semver)
affected
6.2.8 (semver)
affected
6.0.10 (semver)
affected
Description
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests.
Problem types
Execute unauthorized code or commands
Product status
7.4.0 (semver)
7.2.0 (semver)
7.0.0 (semver)
6.4.4 (semver)
6.2.8 (semver)
6.0.10 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-24-130
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.