Multiple authenticated SQL injection via extraParam

Summary

An improper neutralization of special elements used in an SQL command ('SQL injection') [CWE-89] in FortiVoice may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests.

Version Affected Solution
FortiVoice 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiVoice 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above
FortiVoice 6.4 6.4 all versions Migrate to a fixed release
FortiVoice 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by David Maciejak of Fortinet Product Security team.

Timeline

2025-12-09: Initial publication