SQL injections in voice and administrative interface

Summary

An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiVoice may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

Version Affected Solution
FortiVoice 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiVoice 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above

Acknowledgement

Internally discovered and reported by Jaguar Perlas from Burnaby Infosec team.

Timeline

2025-11-18: Initial publication