CVE-2024-55593

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Jan 14, 2025
CWE ID 89

Summary

CVE-2024-55593 is a vulnerability affecting Fortinet FortiWeb versions 6.3.17 to 7.6.1. An attacker can exploit this SQL injection flaw to gain unauthorized access to information. The vulnerability stems from FortiWeb's mishandling of special characters in SQL commands, allowing malicious queries to bypass intended access controls. Successful exploitation could result in data exposure, posing a significant risk to organizations using these impacted FortiWeb versions. It is strongly recommended to apply the necessary patches to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share