logo

A Vulnerability in FortiWeb Could Allow for SQL Injection

ID: a9318af5-0054-548b-9810-f04202f48fe1

STIX ID: report--a9318af5-0054-548b-9810-f04202f48fe1

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-07-08

Date Updated: 2026-04-27

...
...

A SQL injection vulnerability (CVE-2025-25257) has been discovered in FortiWeb that may permit unauthenticated attackers to execute SQL commands via crafted HTTP/HTTPS requests; successful exploitation could lead to arbitrary code execution. The report maps the issue to the ATT&CK tactic 'Initial Access' and technique 'Exploit Public-Facing Application (T1190)'. No evidence of in-the-wild exploitation or affected deployments is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.