CVE-2023-23775: SQL Injection
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23775?
The severity of CVE-2023-23775 is considered high due to its potential to allow an authenticated attacker to execute unauthorized commands.
How do I fix CVE-2023-23775?
To fix CVE-2023-23775, it is recommended to upgrade FortiSOAR to versions 7.2.1 or later, or to a version prior to 7.0.3.
What types of vulnerabilities are associated with CVE-2023-23775?
CVE-2023-23775 is associated with SQL injection vulnerabilities categorized under CWE-89.
Who is affected by CVE-2023-23775?
CVE-2023-23775 affects FortiSOAR versions 7.2.0 and before 7.0.3.
What can an attacker achieve through CVE-2023-23775?
An attacker exploiting CVE-2023-23775 can execute unauthorized code or commands on the affected FortiSOAR systems.