CVE-2022-29059: SQL Injection
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29059?
CVE-2022-29059 is classified as a critical vulnerability due to its potential for SQL Injection and unauthorized database access.
How do I fix CVE-2022-29059?
To fix CVE-2022-29059, upgrade FortiWeb to version 7.0.2 or above, 6.4.3 or higher, 6.3.21 or newer, or 6.2.8 or later.
What causes CVE-2022-29059?
CVE-2022-29059 is caused by improper neutralization of special elements in an SQL command, leading to potential SQL Injection vulnerabilities.
Which FortiWeb versions are affected by CVE-2022-29059?
FortiWeb versions 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, as well as 6.2.7 and below are affected by CVE-2022-29059.
Who can exploit CVE-2022-29059?
A privileged attacker can exploit CVE-2022-29059 to execute unauthorized SQL commands on the log database.