A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-119 |
|
History
Wed, 15 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in FortiDDoS-F Enabling Unauthorized Code Execution |
Tue, 14 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| First Time appeared |
Fortinet
Fortinet fortiddos-f |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:o:fortinet:fortiddos-f:7.2.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortiddos-f:7.2.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortiddos-f |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-04-14T17:35:54.853Z
Reserved: 2026-04-07T15:24:20.512Z
Link: CVE-2026-39815
Updated: 2026-04-14T16:37:02.310Z
Status : Received
Published: 2026-04-14T16:16:46.383
Modified: 2026-04-14T18:17:39.153
Link: CVE-2026-39815
No data.
OpenCVE Enrichment
Updated: 2026-04-15T15:30:06Z