CVE-2024-55593
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Jan 14, 2025
CWE ID 89
Summary
CVE-2024-55593 is a vulnerability affecting Fortinet FortiWeb versions 6.3.17 to 7.6.1. An attacker can exploit this SQL injection flaw to gain unauthorized access to information. The vulnerability stems from FortiWeb's mishandling of special characters in SQL commands, allowing malicious queries to bypass intended access controls. Successful exploitation could result in data exposure, posing a significant risk to organizations using these impacted FortiWeb versions. It is strongly recommended to apply the necessary patches to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiWeb
Affected Vendors
- Fortinet