A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-21-129 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2021-12-08 12:15
Updated : 2021-12-09 21:28
NVD link : CVE-2021-42760
Mitre link : CVE-2021-42760
CVE.ORG link : CVE-2021-42760
JSON object : View
Products Affected
fortinet
- fortiwlm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')