cbcvebase.
CVE-2024-55593
published 2025-01-14

CVE-2024-55593: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to…

PriorityP415low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.41%
34.6th percentile
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet——
fortinetfortiweb——
fortinetfortiweb>= 6.3.6 < 7.6.27.6.2
fortinetfortiweb6.3.6 – 6.3.23—
fortinetfortiweb6.4.0 – 6.4.3—
fortinetfortiweb7.0.0 – 7.0.10—
fortinetfortiweb7.2.0 – 7.2.10—
fortinetfortiweb7.4.0 – 7.4.6—
fortinetfortiweb7.6.0 – 7.6.1—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.