SQL Injection Vulnerabilities in Fortinet FortiADC Management Interface
CVE-2022-26120
5.4MEDIUM
Summary
Multiple instances of improper neutralization of special elements used in SQL commands within the FortiADC management interface could permit an authenticated attacker to execute unauthorized code or commands. This vulnerability arises when specially crafted HTTP requests are sent to exploit the affected versions of FortiADC, potentially compromising the integrity and confidentiality of the system. Active mitigation measures are necessary to safeguard against potential exploitation.
Affected Version(s)
Fortinet FortiADC FortiADC 7.0.0 through 7.0.1, 5.0.0 through 6.2.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved