ZeroHour

CVE-2021-26114

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Vendors
fortinet
Products
fortiwan
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.