CVE-2024-55593
published 2025-01-14CVE-2024-55593: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to…
PriorityP415low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.39%
31.3th percentile
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 6.3.6 < 7.6.2 | 7.6.2 |
| fortinet | fortiweb | 6.3.6 – 6.3.23 | — |
| fortinet | fortiweb | 6.4.0 – 6.4.3 | — |
| fortinet | fortiweb | 7.0.0 – 7.0.10 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.10 | — |
| fortinet | fortiweb | 7.4.0 – 7.4.6 | — |
| fortinet | fortiweb | 7.6.0 – 7.6.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fjp-2975-mx8w: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6
ghsa_unreviewed·2025-01-14
CVE-2024-55593 [LOW] CWE-89 GHSA-4fjp-2975-mx8w: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
Fortinet
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
vendor_fortinet·2025-01-14·CVSS 2.7
CVE-2024-55593 [LOW] CWE-89 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
FG-IR-24-465: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
CVEs: CVE-2024-55593
CWEs: CWE-89
CVSS: 2.7 (low)
Affected products: FortiWeb, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published