SQL Injection Vulnerability in Fortinet FortiWLM Affected by Improper Neutralization
CVE-2021-36184
8.8HIGH
Summary
Inadequate handling of special characters in SQL commands exposes Fortinet FortiWLM versions 8.6.1 and prior to SQL injection attacks, allowing attackers to retrieve sensitive information about devices, users, and the database through crafted HTTP requests. This vulnerability poses significant risks by enabling unauthorized access to critical data.
Affected Version(s)
Fortinet FortiWLM FortiWLM 8.6.1, 8.6.0, 8.5.2, 8.5.1, 8.5.0, 8.4.2, 8.4.1, 8.4.0, 8.3.2, 8.3.1, 8.3.0, 8.2.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved