Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-22-448 |
![]() ![]() ![]() |
History
Tue, 21 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet fortisoar |
|
CPEs | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fortinet
Fortinet fortisoar |

Status: PUBLISHED
Assigner: fortinet
Published: 2024-06-11T14:32:00.651Z
Updated: 2024-08-02T10:42:26.252Z
Reserved: 2023-01-18T08:30:21.306Z
Link: CVE-2023-23775

Updated: 2024-08-02T10:42:26.252Z

Status : Analyzed
Published: 2024-06-11T15:15:53.723
Modified: 2025-01-21T21:56:39.483
Link: CVE-2023-23775

No data.