> Unauthenticated SQL injection in GUI
[DATE: 08/07/2025 07:00]
[LANGUAGE: EN]
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.Fortinet has observed this to be exploited in the wild on FortiWeb. Revised on 2025-07-18 00:00:00