A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
References
Link Resource
https://www.fortiguard.com/psirt/FG-IR-20-124 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fortinet

Published: 2021-01-14T16:07:20

Updated: 2021-01-14T16:07:20

Reserved: 2020-11-24T00:00:00


Link: CVE-2020-29015

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-14T16:15:17.883

Modified: 2021-01-20T20:59:04.870


Link: CVE-2020-29015

JSON object: View

cve-icon Redhat Information

No data.

CWE