CVE-2024-55593: SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55593?
CVE-2024-55593 has been classified as a critical vulnerability due to the potential for information disclosure via SQL injection.
What versions of Fortinet FortiWeb are affected by CVE-2024-55593?
CVE-2024-55593 affects Fortinet FortiWeb versions 6.3.17 through 7.6.1.
How do I fix CVE-2024-55593?
To mitigate CVE-2024-55593, upgrade your Fortinet FortiWeb deployment to a version released after 7.6.1.
What type of attack does CVE-2024-55593 enable?
CVE-2024-55593 enables attackers to conduct SQL injection attacks, allowing them to execute crafted SQL queries.
What information can be disclosed through CVE-2024-55593?
CVE-2024-55593 allows attackers to gain unauthorized access to sensitive information stored in the database through SQL injection.