CVE Database
/

CVE-2020-29015

Back to search

CVE-2020-29015

Published: Jan 14, 2021

Modified: Oct 25, 2024

PUBLISHED

Description

A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.

VendorProductVersions

n/a

Fortinet FortiWeb

affected
FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now