CVE-2025-24474: SQL injection in forward module
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiAnalyzer 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; and FortiAnalyzer Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker with high privilege to extract database information via crafted requests.
Other sources
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager and FortiAnalyzer may allow an authenticated attacker with high privilege to extract database information via crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24474?
CVE-2025-24474 has a significant severity due to its potential for SQL injection attacks.
How do I fix CVE-2025-24474?
To address CVE-2025-24474, upgrade FortiManager or FortiManager Cloud to version 7.6.2 or 7.4.7 as applicable.
Which versions are affected by CVE-2025-24474?
CVE-2025-24474 affects FortiManager versions 7.6.0 to 7.6.1, 7.4.0 to 7.4.6, and older versions 7.2, 7.0, and 6.4.
What products are impacted by CVE-2025-24474?
CVE-2025-24474 impacts FortiManager, FortiManager Cloud, FortiAnalyzer, and FortiAnalyzer Cloud.
Is there a workaround for CVE-2025-24474?
There are no specific workarounds for CVE-2025-24474, so applying the remedial update is recommended.