CVE-2020-29015: Fortinet FortiWeb

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.

Affected products

  • Fortinet FortiWeb: before 6.2.4 (fixed in 6.2.4); from 6.3.0, up to and including 6.3.7

Published 2021-01-14. Last modified 2026-06-17.