TT-CSIRT – 441.10.07.25 – Fortinet Security Advisories – SQL injection in GUI

TT-CSIRT – 441.10.07.25 – Fortinet Security Advisories – SQL injection in GUI

Please be advised of the critical vulnerability CVE-2025-25257, which affects FortiWeb. This issue stems from improper handling of special characters in SQL commands, leading to a SQL Injection vulnerability (CWE-89). This vulnerability enables an attacker to execute unauthorized SQL code by sending specially crafted HTTP or HTTPS requests.

Affected Versions and solutions:

VersionAffectedSolution
FortiWeb 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiWeb 7.47.4.0 through 7.4.7Upgrade to 7.4.8 or above
FortiWeb 7.27.2.0 through 7.2.10Upgrade to 7.2.11 or above
FortiWeb 7.07.0.0 through 7.0.10Upgrade to 7.0.11 or above

Workaround

Disable HTTP/HTTPS administrative interface

References:

https://www.fortiguard.com/psirt/FG-IR-25-151

If you have any queries, comments or require assistance, please feel free to contact TT-CSIRT via contacts@ttcsirt.gov.tt