CVE detail
CVE-2022-29059 — CVE-2022-29059
Published 2025-03-14 · Modified 2026-06-17 · Vendor fortinet · Product fortiweb · Source nvd
LOW
severity
CVSS-derived band
0.0040
EPSS probability
exploitation probability, 30d
33.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References