Blind SQL injection vulnerability

Summary

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise may allow an authenticated attacker to perform a blind sql injection attack via sending crafted HTTP or HTTPS requests

Version Affected Solution
FortiVoice 7.2 Not affected Not Applicable
FortiVoice 7.0 7.0.0 through 7.0.1 Upgrade to 7.0.2 or above
FortiVoice 6.4 6.4.0 through 6.4.8 Upgrade to 6.4.9 or above
FortiVoice 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Hritik Sateesh from Fortinet's Burnaby Infosec team.

Timeline

2025-01-14: Initial publication