CVE-2020-29011: FortiSandbox - Pervarsive SQL Injection
Instances of SQL Injection vulnerabilities in FortiSandbox's checksum search and MTA-quarantine modules may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
Other sources
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29011?
CVE-2020-29011 refers to instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox.
How does CVE-2020-29011 impact FortiSandbox?
CVE-2020-29011 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter of FortiSandbox.
What versions of FortiSandbox are affected by CVE-2020-29011?
FortiSandbox versions 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 are affected by CVE-2020-29011.
How severe is CVE-2020-29011?
CVE-2020-29011 has a severity score of 8.8 (high severity).
How can I fix CVE-2020-29011?
To fix CVE-2020-29011, update FortiSandbox to a version beyond 3.2.2 or 3.1.4 as soon as possible.