SQL injection in FortiSandbox - CVE-2024-54026
Published: May 7, 2025
FortiSandbox
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within the device del feature. A remote privileged user can send a specially crafted HTTP request and execute arbitrary SQL queries in the application's database, which can lead to privilege escalation.