GHSA-mj4r-rpwm-gg33
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 25, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.