SQL Injection in script handlers
Summary
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiWLM may allow an unauthenticated user to taint database data and extract sensitive informations via crafted HTTP requests to alarm and device handlers.
Affected Products
FortlWLM version 8.6.1 and below
FortiWLM version 8.5.3 and below
FortiWLM 8.2 all versions
FortiWLM 8.3 all versions
FortiWLM 8.4 all versions
Solutions
Upgrade to FortiWLM version 8.6.2 or above.
Upgrade to FortiWLM version 8.5.4 or above.
Acknowledgement
Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.Timeline
2021-12-07: Initial publication