CVE-2024-55593: Fortinet FortiWeb

Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

Affected products

  • Fortinet FortiWeb: from 6.3.6, before 7.6.2 (fixed in 7.6.2)

Published 2025-01-14. Last modified 2026-06-17.