{ "id": "CVE-2024-54026", "sourceIdentifier": "psirt@fortinet.com", "published": "2025-03-11T15:15:43.307", "lastModified": "2025-03-11T15:15:43.307", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23.4, FortiSandbox at least 4.4.0 through 4.4.6 and 4.2.0 through 4.2.7 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests." }, { "lang": "es", "value": "Una neutralizaci\u00f3n incorrecta de elementos especiales utilizados en un comando sql ('sql injection') en Fortinet FortiSandbox Cloud versi\u00f3n 23.4, FortiSandbox al menos 4.4.0 a 4.4.6 y 4.2.0 a 4.2.7 y 4.0.0 a 4.0.5 y 3.2.0 a 3.2.4 y 3.1.0 a 3.1.5 y 3.0.0 a 3.0.7 permite a un atacante ejecutar c\u00f3digo o comandos no autorizados a trav\u00e9s de solicitudes HTTP espec\u00edficamente manipuladas." } ], "metrics": { "cvssMetricV31": [ { "source": "psirt@fortinet.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 1.4 } ] }, "weaknesses": [ { "source": "psirt@fortinet.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-89" } ] } ], "references": [ { "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-353", "source": "psirt@fortinet.com" } ] }