A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-21-129 | Patch Vendor Advisory |
Configurations
Information
Published : 2021-12-08 04:15
Updated : 2021-12-09 13:28
NVD link : CVE-2021-42760
Mitre link : CVE-2021-42760
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
fortinet
- fortiwlm