SQL Injection in API EndPoints

Summary

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiWeb API endpoints may allow an authenticated attacker with admin privileges to gain signatures information via crafted SQL queries. 

Version Affected Solution
FortiWeb 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiWeb 7.4 7.4 all versions Migrate to a fixed release
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 6.4 all versions Migrate to a fixed release
FortiWeb 6.3 6.3.6 through 6.3.23 Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane of GMO Cybersecurity by Ierae for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication