FG-IR-26-111: SQL Injection via JSON RPC API
An improper neutralization of special elements used in an SQL command ('SQL injection') [CWE-89] in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-111?
The severity of FG-IR-26-111 is classified as high due to the potential for authenticated attackers to execute unauthorized SQL commands.
How do I fix FG-IR-26-111?
To fix FG-IR-26-111, upgrade to FortiAnalyzer and FortiManager versions 7.6.5 or later, or 7.4.9 or later for applicable versions.
Which products are affected by FG-IR-26-111?
FG-IR-26-111 affects FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud versions 7.6.0 to 7.6.4 and 7.4.0 to 7.4.8.
Who can exploit FG-IR-26-111?
FG-IR-26-111 can be exploited by an authenticated privileged attacker who gains access to the vulnerable systems.
What type of vulnerability is FG-IR-26-111?
FG-IR-26-111 is an SQL Injection vulnerability classified under CWE-89 due to improper neutralization of input in SQL commands.