CVE-2024-35275

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 68.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9

Affected Packages6 packages

NVDfortinet/fortimanager7.4.07.4.3
NVDfortinet/fortianalyzer7.4.07.4.4
NVDfortinet/fortimanager_cloud7.4.17.4.3
NVDfortinet/fortianalyzer_cloud7.4.17.4.3
CVEListV5fortinet/fortimanager7.4.07.4.2

🔴Vulnerability Details

2
GHSA
GHSA-rp6x-j4c5-4rvc: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 72025-01-14
CVEList
CVE-2024-35275: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 72025-01-14

📋Vendor Advisories

1
Fortinet
SQL injections in sdnproxy daemon2025-01-14
CVE-2024-35275 (HIGH CVSS 8.8) | A improper neutralization of specia | cvebase.io