VYPR
Critical severity9.8NVD Advisory· Published Jan 14, 2021· Updated Jun 17, 2026

CVE-2020-29015

CVE-2020-29015

Description

A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Fortinet/Fortiweb2 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: <6.2.4
    • (no CPE)range: 6.3.0 through 6.3.7 and before 6.2.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.