PSIRT Advisories

FortiWLM - SQL Injection in script handlers

Summary

An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiWLM may allow an unauthenticated user to taint database data and extract sensitive informations via crafted HTTP requests to alarm and device handlers.

Affected Products

FortlWLM version 8.6.1 and below

Solutions

Upgrade to FortiWLM version 8.6.2 or above.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security team.