Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-051 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fortinet
Published: 2022-07-18T16:41:00
Updated: 2022-07-18T16:41:00
Reserved: 2022-02-25T00:00:00
Link: CVE-2022-26120
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-18T18:15:09.120
Modified: 2022-07-25T14:08:51.273
Link: CVE-2022-26120
JSON object: View
Redhat Information
No data.
CWE