Vulnerability Details CVE-2023-23775
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-23775
-
cpe:2.3:a:fortinet:fortisoar:7.0.0
-
cpe:2.3:a:fortinet:fortisoar:7.0.1
-
cpe:2.3:a:fortinet:fortisoar:7.0.2
-
cpe:2.3:a:fortinet:fortisoar:7.0.3
-
cpe:2.3:a:fortinet:fortisoar:7.2.0