Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-448 | 
                     | 
            
History
                    Tue, 21 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Fortinet
         Fortinet fortisoar  | 
|
| CPEs | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Fortinet
         Fortinet fortisoar  | 
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T10:42:26.252Z
Reserved: 2023-01-18T08:30:21.306Z
Link: CVE-2023-23775
Updated: 2024-08-02T10:42:26.252Z
Status : Analyzed
Published: 2024-06-11T15:15:53.723
Modified: 2025-01-21T21:56:39.483
Link: CVE-2023-23775
No data.