CVE-2021-42760

HIGH

Fortinet FortiWLM < 8.6.1 - SQL Injection via Crafted Requests

Title source: llm
STIX 2.1

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-129

Scores

CVSS v3 8.8
EPSS 0.0042
EPSS Percentile 62.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
fortinet/fortiwlm < 8.6.1
Published Dec 08, 2021
Tracked Since Feb 18, 2026