CVE-2023-37931

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
14/01/2025
Last modified:
22/07/2025

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via sending crafted HTTP or HTTPS requests

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:* 6.0.0 (including) 6.4.9 (excluding)
cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.2 (excluding)


References to Advisories, Solutions, and Tools