CVE-2022-29059

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Mar 14, 2025
CWE ID 89

Summary

CVE-2022-29059 is a SQL injection vulnerability affecting FortiWeb versions 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, and 6.2.7 and below. This issue, identified as CWE-89, arises due to an improper handling of special elements in SQL commands. A privileged attacker can exploit this flaw by inputting specifically crafted string parameters, potentially enabling the execution of SQL commands over the log database. This vulnerability poses a significant risk as it allows attackers to access and manipulate sensitive data. FortiWeb users are strongly advised to install available patches or upgrades to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share