A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2021-01-14T16:07:20

Updated: 2024-08-04T16:48:01.571Z

Reserved: 2020-11-24T00:00:00

Link: CVE-2020-29015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-14T16:15:17.883

Modified: 2021-01-20T20:59:04.870

Link: CVE-2020-29015

cve-icon Redhat

No data.