Published:2025/01/21 Last Updated:2025/01/21
JVN#83855727
FortiWeb vulnerable to SQL injection
Overview
FortiWeb provided by Fortinet, Inc. contains an SQL injection vulnerability.
Products Affected
- FortiWeb versions prior to 7.6.2
Description
FortiWeb provided by Fortinet, Inc. contains an SQL injection vulnerability (CWE-89, CVE-2024-55593).
Impact
Information in the FortiWeb database may be obtained by a user who can log in to the product.
Solution
Update the software
Update the software to the latest version according to the information provided by the developer.
The developer fixed the vulnerability in the following version:
- FortiWeb version 7.6.2 and later
Vendor Status
Vendor | Link |
Fortinet, Inc. | SQL Injection in API EndPoints |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score:
2.7
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Credit
Kentaro Kawane of GMO Cybersecurity by Ierae reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
|
JVN iPedia |
JVNDB-2025-000003 |