FortiWeb vulnerable to SQL injection

Overview

FortiWeb provided by Fortinet, Inc. contains an SQL injection vulnerability.

Products Affected

  • FortiWeb versions prior to 7.6.2

For more information, refer to the information provided by the developer.

Description

FortiWeb provided by Fortinet, Inc. contains an SQL injection vulnerability (CWE-89, CVE-2024-55593).

Impact

Information in the FortiWeb database may be obtained by a user who can log in to the product.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.
The developer fixed the vulnerability in the following version:

  • FortiWeb version 7.6.2 and later

Credit

Kentaro Kawane of GMO Cybersecurity by Ierae reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

نوشته های مشابه