CVE-2022-29059
CVSS 3.1 Score 2.7 of 10 (low)
Details
Summary
CVE-2022-29059 is a SQL injection vulnerability affecting FortiWeb versions 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, and 6.2.7 and below. This issue, identified as CWE-89, arises due to an improper handling of special elements in SQL commands. A privileged attacker can exploit this flaw by inputting specifically crafted string parameters, potentially enabling the execution of SQL commands over the log database. This vulnerability poses a significant risk as it allows attackers to access and manipulate sensitive data. FortiWeb users are strongly advised to install available patches or upgrades to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiWeb
Affected Vendors
- Fortinet