CVE-2024-54026
published 2025-03-11CVE-2024-54026: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.39%
31.0th percentile
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 3.0.0 < 4.4.7 | 4.4.7 |
| fortinet | fortisandbox | 3.0.0 – 3.0.7 | — |
| fortinet | fortisandbox | 3.1.0 – 3.1.5 | — |
| fortinet | fortisandbox | 3.2.0 – 3.2.4 | — |
| fortinet | fortisandbox | 4.0.0 – 4.0.6 | — |
| fortinet | fortisandbox | 4.2.1 – 4.2.8 | — |
| fortinet | fortisandbox | 4.4.0 – 4.4.6 | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandboxcloud | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is an error-based SQL injection on the device delete ('device del') feature of FortiSandbox, triggered via crafted HTTP requests. ↗
- →Attack vector is HTTP requests with specially crafted SQL injection payloads targeting the FortiSandbox device deletion endpoint. ↗
- ·Affected versions span a wide range: FortiSandbox 3.0, 3.1, 3.2 (all versions), 4.0 (all versions), 4.2 (all versions), 4.4.0 through 4.4.6, and FortiSandbox Cloud 24.1. Detection and patching scope should cover all these versions. ↗
- ·CVSS score is 4.3 (Medium), which may affect prioritization, but successful exploitation allows unauthorized code or command execution via SQL injection (CWE-89). ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j6hj-9xq3-x536: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23
ghsa_unreviewed·2025-03-11
CVE-2024-54026 [MEDIUM] CWE-89 GHSA-j6hj-9xq3-x536: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23.4, FortiSandbox at least 4.4.0 through 4.4.6 and 4.2.0 through 4.2.7 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Fortinet
error based SQLI on device del feature
vendor_fortinet·2025-03-11·CVSS 4.3
CVE-2024-54026 [MEDIUM] CWE-89 error based SQLI on device del feature
FG-IR-24-353: error based SQLI on device del feature
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVEs: CVE-2024-54026
CWEs: CWE-89
CVSS: 4.3 (medium)
Affected products: FortiSandbox, FortiSandboxcloud, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-11
Published