CVE-2022-26120: SQL Injection
Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26120?
CVE-2022-26120 is a vulnerability that allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
What is the severity of CVE-2022-26120?
CVE-2022-26120 has a severity level of high, with a severity value of 8.8.
Which software is affected by CVE-2022-26120?
FortiADC management interface versions 7.0.0 through 7.0.1, and versions 5.0.0 through 6.2.2, are affected by CVE-2022-26120.
How can an attacker exploit CVE-2022-26120?
An attacker can exploit CVE-2022-26120 by sending specifically crafted HTTP requests to the FortiADC management interface.
Is there a fix for CVE-2022-26120?
Yes, it is recommended to upgrade to a fixed version of FortiADC management interface. Please refer to the vendor's advisory for more information.