FG-IR-20-171: FortiSandbox - Pervarsive SQL Injection
Published Aug 3, 2021
·Updated
Instances of SQL Injection vulnerabilities in FortiSandbox's checksum search and MTA-quarantine modules may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
Affected Software
1 affected component
Fortinet FortiSandbox
Event History
Aug 3, 2021
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 25, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-20-171?
The severity of FG-IR-20-171 is high due to the potential for code execution via SQL injection.
2
How do I fix FG-IR-20-171?
To fix FG-IR-20-171, update FortiSandbox to the latest version as recommended by Fortinet.
3
What software versions are affected by FG-IR-20-171?
FG-IR-20-171 affects various versions of Fortinet FortiSandbox software.
4
What type of attack does FG-IR-20-171 involve?
FG-IR-20-171 involves SQL injection attacks that can be executed through manipulated HTTP requests.
5
Who can exploit FG-IR-20-171?
FG-IR-20-171 can be exploited by authenticated attackers who have access to the affected system.