First published: Tue Jan 14 2025(Updated: )
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via sending crafted HTTP or HTTPS requests
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiVoice Enterprise | >=7.0.0<=7.0.1<6.4.8 |
Please upgrade to FortiVoice version 7.0.2 or above Please upgrade to FortiVoice version 6.4.9 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37931 is categorized as a high severity SQL injection vulnerability.
To fix CVE-2023-37931, update FortiVoice Enterprise to version 6.4.8 or later, or to version 7.0.2 or later.
CVE-2023-37931 affects FortiVoice Enterprise versions 7.0.0 through 7.0.1 and versions prior to 6.4.8.
CVE-2023-37931 is an improper neutralization of input and allows for SQL injection attacks.
An authenticated attacker can perform a blind SQL injection attack through crafted HTTP or HTTPS requests.