SQL Injection in script handlers

Summary

An improper neutralization of special elements [CWE-79] used in an SQL command vulnerability ('SQL Injection') [CWE-89] in FortiWLM may allow an authenticated attacker to disclose sensitive information via crafted HTTP requests to various controllers.

Affected Products

FortiWLM version 8.6.1 and below are impacted

Solutions

Upgrade to FortiWLM version 8.6.2 or earlier

Acknowledgement

Internally discovered and reported by Mattia Fecit of the Fortinet Product Security Team.