FortiSOAR is vulnerable to sql injection in Event Auth API via uuid parameter

Summary

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR Event Auth API may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.

Version Affected Solution
FortiSOAR on-premise 7.5 Not affected Not Applicable
FortiSOAR on-premise 7.4 Not affected Not Applicable
FortiSOAR on-premise 7.3 Not affected Not Applicable
FortiSOAR on-premise 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiSOAR on-premise 7.0 7.0 all versions Migrate to a fixed release
FortiSOAR on-premise 6.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Pradeep Gurav of Fortinet Software Development team.

Timeline

2024-06-11: Initial publication