← Back to browse · API

CVE-2023-34991

Severity
CRITICAL
CVSS
9.3
EPSS
0.28783
Risk score
47.27
CISA KEV
No
PoC
No
Published
2023-11-14
Modified
2025-12-16
First seen
2026-08-07
Aliases
EUVD-2023-39029, GHSA-HG7C-7628-52R9
Products
Fortinet:FortiWLM 8.2.2, Fortinet:FortiWLM 8.3.0 ≤8.3.2, Fortinet:FortiWLM 8.4.0 ≤8.4.2, Fortinet:FortiWLM 8.5.0 ≤8.5.4, Fortinet:FortiWLM 8.6.0 ≤8.6.5
Sources
euvd EUVD-2023-39029

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.

References