CVE-2024-35275: Fortinet Fortianalyzer
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
Affected products
- Fortinet Fortianalyzer: from 7.4.0, before 7.4.4 (fixed in 7.4.4)
- Fortinet Fortianalyzer Cloud: from 7.4.1, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiManager: from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiManager Cloud: from 7.4.1, before 7.4.3 (fixed in 7.4.3)
Published 2025-01-14. Last modified 2026-06-17.