SQL injection in forward module

Summary

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager and FortiAnalyzer may allow an authenticated attacker with high privilege to extract database information via crafted requests.

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiAnalyzer 7.2 7.2 all versions Migrate to a fixed release
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer Cloud 7.6 Not affected Not Applicable
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.6 Upgrade to 7.4.7 or above
FortiAnalyzer Cloud 7.2 7.2 all versions Migrate to a fixed release
FortiAnalyzer Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiManager 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiManager 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiManager 7.2 7.2 all versions Migrate to a fixed release
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager Cloud 7.6 Not affected Not Applicable
FortiManager Cloud 7.4 7.4.1 through 7.4.6 Upgrade to 7.4.7 or above
FortiManager Cloud 7.2 7.2 all versions Migrate to a fixed release
FortiManager Cloud 7.0 7.0.1 through 7.0.13 Migrate to a fixed release
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Jaguar Perlas of Fortinet Burnaby InfoSec team.

Timeline

2025-07-08: Initial publication
2025-07-09: Add acknowledgement