CVE-2024-35275: SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35275?
CVE-2024-35275 has a high severity rating due to the potential for privilege escalation via SQL injection.
How do I fix CVE-2024-35275?
To fix CVE-2024-35275, update Fortinet FortiAnalyzer and FortiManager to version 7.4.3 or later.
Which versions of Fortinet software are affected by CVE-2024-35275?
CVE-2024-35275 affects FortiAnalyzer versions 7.4.0 to 7.4.2 and FortiManager versions 7.4.0 to 7.4.2.
What type of vulnerability is CVE-2024-35275?
CVE-2024-35275 is an SQL injection vulnerability that allows attackers to escalate privileges.
What are the implications of exploiting CVE-2024-35275?
Exploitation of CVE-2024-35275 can lead to unauthorized access and elevation of privileges on affected Fortinet devices.