Security Advisory

CVE-2022-29059

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-14 15:45:33
Last updated 2025-03-14 17:52:08
Assigner fortinet
State PUBLISHED

Description

An improper neutralization of special elements used in an SQL command (SQL Injection) vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.