cbcvebase.
CVE-2024-55593
published 2025-01-14

CVE-2024-55593: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to…

PriorityP415low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.39%
31.3th percentile
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiweb
fortinetfortiweb>= 6.3.6 < 7.6.27.6.2
fortinetfortiweb6.3.6 – 6.3.23
fortinetfortiweb6.4.0 – 6.4.3
fortinetfortiweb7.0.0 – 7.0.10
fortinetfortiweb7.2.0 – 7.2.10
fortinetfortiweb7.4.0 – 7.4.6
fortinetfortiweb7.6.0 – 7.6.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.