A Vulnerability in FortiWeb Could Allow for SQL Injection
ID: a9318af5-0054-548b-9810-f04202f48fe1
STIX ID: report--a9318af5-0054-548b-9810-f04202f48fe1
Feed Name: CISecurity.org Advisories
Threat Score
A SQL injection vulnerability (CVE-2025-25257) has been discovered in FortiWeb that may permit unauthenticated attackers to execute SQL commands via crafted HTTP/HTTPS requests; successful exploitation could lead to arbitrary code execution. The report maps the issue to the ATT&CK tactic 'Initial Access' and technique 'Exploit Public-Facing Application (T1190)'. No evidence of in-the-wild exploitation or affected deployments is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
