FG-IR-25-151: Unauthenticated SQL injection in GUI
Published Jul 8, 2025
·Updated
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Affected Software
4 affected componentsFixes available
Fortinet FortiWeb>=7.6.0<=7.6.3
Fortinet FortiWeb>=7.4.0<=7.4.7
Fortinet FortiWeb>=7.2.0<=7.2.10
Fortinet FortiWeb>=7.0.0<=7.0.10
Event History
Jul 8, 2025
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-25-151?
The severity of FG-IR-25-151 is high due to its potential for SQL Injection attacks.
2
How do I fix FG-IR-25-151?
To fix FG-IR-25-151, upgrade FortiWeb to versions 7.6.4, 7.4.8, 7.2.11, or 7.0.11 or higher.
3
What systems are affected by FG-IR-25-151?
FG-IR-25-151 affects FortiWeb versions between 7.6.0 and 7.6.3, 7.4.0 and 7.4.7, 7.2.0 and 7.2.10, and 7.0.0 and 7.0.10.
4
Can an attacker exploit FG-IR-25-151 remotely?
Yes, an unauthenticated attacker can exploit FG-IR-25-151 remotely via crafted HTTP or HTTPS requests.
5
What type of vulnerability is FG-IR-25-151 classified as?
FG-IR-25-151 is classified as an SQL Injection vulnerability under CWE-89.