Fortinet FortiWeb
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*
- <= 7.0.1
- <= 6.4.2
- <= 6.3.20
- <= 6.2.7
A SQL injection vulnerability has been identified in Fortinet FortiWeb versions through 7.0.1, through 6.4.2, through 6.3.20, and through 6.2.7. This vulnerability allows a privileged attacker to execute SQL commands on the log database by using specially crafted string parameters.
Exploitation of this vulnerability could lead to unauthorized execution of SQL commands, potentially allowing for manipulation of the log database or extraction of sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.