CVE-2020-29015: [FortiWeb] Unauthenticated user can read and write file on the system (Blind SQL Injection)
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
Other sources
A blind SQL injection in the user interface of FortiWeb may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29015?
CVE-2020-29015 has a medium severity rating due to the potential for unauthenticated remote SQL injection attacks.
How do I fix CVE-2020-29015?
To remediate CVE-2020-29015, update FortiWeb to version 6.3.8 or later, or 6.2.4 or later.
What versions of FortiWeb are affected by CVE-2020-29015?
CVE-2020-29015 affects FortiWeb versions 6.3.0 through 6.3.7 and versions before 6.2.4.
Can CVE-2020-29015 be exploited remotely?
Yes, CVE-2020-29015 can be exploited remotely by an unauthenticated attacker.
What type of vulnerability is CVE-2020-29015?
CVE-2020-29015 is classified as a blind SQL injection vulnerability.