Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-448 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fortinet
Published: 2024-06-11T14:32:00.651Z
Updated: 2024-06-11T18:46:10.782Z
Reserved: 2023-01-18T08:30:21.306Z
Link: CVE-2023-23775
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-06-11T15:15:53.723
Modified: 2024-06-13T18:36:45.417
Link: CVE-2023-23775
JSON object: View
Redhat Information
No data.
CWE