CVE-2025-24474

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versi

Severity
Low 2.6
CVSS 3.1
Exploited
Not listed
EPSS
0.002
16.0th percentile
Discovered by
Not disclosed
Published
Jul 8, 2025
Assigned by fortinet

Description

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiAnalyzer 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; and FortiAnalyzer Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker with high privilege to extract database information via crafted requests.

Weakness: CWE-89

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer

Vendor remediation

Please upgrade to FortiManager version 7.6.2 or above Please upgrade to FortiManager version 7.4.7 or above Please upgrade to FortiAnalyzer version 7.6.2 or above Please upgrade to FortiAnalyzer version 7.4.7 or above Please upgrade to FortiAnalyzer Cloud version 7.6.2 or above Please upgrade to FortiAnalyzer Cloud version 7.4.7 or above Please upgrade to FortiManager Cloud version 7.6.2 or above Please upgrade to FortiManager Cloud version 7.4.7 or above