ZeroHour

CVE-2021-42760

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.

Vendors
fortinet
Products
fortiwlm
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.