Description
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiSOAR version 7.2.1 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27861 | Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-448 |
|
History
Tue, 21 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortisoar |
|
| CPEs | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisoar |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T10:42:26.252Z
Reserved: 2023-01-18T08:30:21.306Z
Link: CVE-2023-23775
Updated: 2024-08-02T10:42:26.252Z
Status : Analyzed
Published: 2024-06-11T15:15:53.723
Modified: 2025-01-21T21:56:39.483
Link: CVE-2023-23775
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD