FG-IR-24-353: error based SQLI on device del feature
Published Mar 11, 2025
·Updated
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected Software
6 affected componentsFixes available
Fortinet FortiSandbox>=4.4.0<=4.4.6
Fortinet FortiSandbox>=4.2
Fortinet FortiSandbox>=4.0
Fortinet FortiSandbox>=3.2
Fortinet FortiSandbox>=3.1
Fortinet FortiSandbox>=3.0
Event History
Mar 11, 2025
Advisory Published
via FortiGuard·12:00 AM
May 7, 2025
Advisory Published
via FortiGuard·08:31 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-353?
The severity of FG-IR-24-353 is high due to the potential for unauthorized code execution via SQL injection.
2
How do I fix FG-IR-24-353?
To fix FG-IR-24-353, update to FortiSandbox version 4.4.7 or later.
3
What versions of FortiSandbox are affected by FG-IR-24-353?
FortiSandbox versions from 4.4.0 to 4.4.6 and all versions prior to 4.4.7 are affected by FG-IR-24-353.
4
What is the nature of the vulnerability identified in FG-IR-24-353?
FG-IR-24-353 is an SQL injection vulnerability that improperly neutralizes special elements in SQL commands.
5
Who can exploit the FG-IR-24-353 vulnerability?
A privileged attacker can exploit the FG-IR-24-353 vulnerability by sending specifically crafted HTTP requests.