A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-21-129 | Patch Vendor Advisory |
https://fortiguard.com/advisory/FG-IR-21-129 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 06:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/advisory/FG-IR-21-129 - Patch, Vendor Advisory |
Information
Published : 2021-12-08 12:15
Updated : 2024-11-21 06:28
NVD link : CVE-2021-42760
Mitre link : CVE-2021-42760
CVE.ORG link : CVE-2021-42760
JSON object : View
Products Affected
fortinet
- fortiwlm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')