SQL Injection via API

Summary

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiDDoS-F may allow an authenticated attacker to run arbitrary SQL queries on the database by sending crafted HTTP requests.

Version Affected Solution
FortiDDoS-F 7.2 7.2.1 through 7.2.2 Upgrade to 7.2.3 or above
FortiDDoS-F 7.0 Not affected Not Applicable
FortiDDoS-F 6.6 Not affected Not Applicable
FortiDDoS-F 6.5 Not affected Not Applicable
FortiDDoS-F 6.4 Not affected Not Applicable
FortiDDoS-F 6.3 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by David Maciejak of Fortinet Product Security team.

Timeline

2026-04-14: Initial publication