SQL Injection in delete filter component

Summary

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb delete log filter component may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.

Affected Products

At least
FortiWeb version 7.0.0 through 7.0.1
FortiWeb 6.4 all versions
FortiWeb 6.3 all versions
FortiWeb version 6.2.3 through 6.2.8
FortiWeb 6.1 all versions are not affected
FortiWeb 6.0 all versions are not affected
FortiWeb 5.9 all versions are not affected

Solutions

Upgrade to FortiWeb version 7.0.2 or above.

Acknowledgement

Internally discovered and reported by Giulia Clerici of the Fortinet Product Security team.

Timeline

2022-09-06: Initial publication