Critical severity9.8NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-34991
CVE-2023-34991
Description
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.
Affected products
108.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.4.0 through 8.4.2, 8.3.0 through 8.3.2, 8.2.2+ 9 more
- (no CPE)range: 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.4.0 through 8.4.2, 8.3.0 through 8.3.2, 8.2.2
- cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*range: >=8.5.0,<=8.5.4
- cpe:2.3:a:fortinet:fortiwlm:8.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiwlm:8.4.2:*:*:*:*:*:*:*
- (no CPE)range: 8.6.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-142nvdVendor Advisory
News mentions
0No linked articles in our index yet.