CVE-2025-25257
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Summary dbcve.org
SQL injection vulnerability in FortiWeb's web interface allows unauthenticated remote attackers to execute arbitrary SQL commands via specially crafted HTTP/HTTPS requests. The flaw exists in the parameter handling of specific API endpoints that fail to properly sanitize user input before incorporating it into SQL queries.
Mitigation
Apply Fortinet's available firmware updates for affected versions (7.6.4, 7.4.8, 7.2.11, 7.0.11 or later). Until patching is feasible, restrict network access to FortiWeb management interfaces to trusted IPs only via ACLs.