• About
  • Disclaimer
  • Privacy Policy
  • Contact
Thursday, July 17, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

Fortinet Releases Patch for Crucial SQL Injection Flaw in FortiWeb (CVE-2025-25257)

Md Sazzad Hossain by Md Sazzad Hossain
0
Fortinet Releases Patch for Crucial SQL Injection Flaw in FortiWeb (CVE-2025-25257)
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Jul 11, 2025Ravie LakshmananUnited States

SQL Injection Flaw in FortiWeb

Fortinet has launched fixes for a crucial safety flaw impacting FortiWeb that might allow an unauthenticated attacker to run arbitrary database instructions on inclined situations.

Tracked as CVE-2025-25257, the vulnerability carries a CVSS rating of 9.6 out of a most of 10.0.

“An improper neutralization of particular parts utilized in an SQL command (‘SQL Injection’) vulnerability [CWE-89] in FortiWeb could enable an unauthenticated attacker to execute unauthorized SQL code or instructions through crafted HTTP or HTTPs requests,” Fortinet stated in an advisory launched this week.

Cybersecurity

The shortcoming impacts the next variations –

  • FortiWeb 7.6.0 by way of 7.6.3 (Improve to 7.6.4 or above)
  • FortiWeb 7.4.0 by way of 7.4.7 (Improve to 7.4.8 or above)
  • FortiWeb 7.2.0 by way of 7.2.10 (Improve to 7.2.11 or above)
  • FortiWeb 7.0.0 by way of 7.0.10 (Improve to 7.0.11 or above)

Kentaro Kawane from GMO Cybersecurity, who was not too long ago credited with reporting a set of crucial flaws in Cisco Id Providers and ISE Passive Id Connector (CVE-2025-20286, CVE-2025-20281, and CVE-2025-20282), has been acknowledged for locating the problem.

In an evaluation printed immediately, watchTowr Labs stated the issue is rooted in a operate known as “get_fabric_user_by_token” that is related to the Material Connector part, which acts as a bridge between FortiWeb and different Fortinet merchandise.

The operate, in flip, is invoked from one other operate named “fabric_access_check,” that is known as from three totally different API endpoints: “/api/material/system/standing,” “/api/v[0-9]/material/widget/[a-z]+,” and “/api/v[0-9]/material/widget.”

The problem is that attacker-controlled enter – handed through a Bearer token Authorization header in a specifically crafted HTTP request – is handed on to an SQL database question with out satisfactory sanitization to be sure that it isn’t dangerous and doesn’t embrace any malicious code.

The assault could be prolonged additional to distant code execution by embedding a SELECT … INTO OUTFILE assertion to jot down a malicious payload to a file within the underlying working system by benefiting from the truth that the question is run because the “mysql” consumer, and execute it through Python.

Cybersecurity

“The brand new model of the operate replaces the earlier format-string question with ready statements – an inexpensive try to forestall easy SQL injection,” safety researcher Sina Kheirkhah stated.

As momentary workarounds till the required patches could be utilized, customers are advisable to disable HTTP/HTTPS administrative interface.

With flaws in Fortinet gadgets having been exploited by menace actors prior to now, it is important that customers transfer rapidly to replace to the newest model to mitigate potential dangers.

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we put up.



You might also like

Why Your Wi-Fi Works however Your Web Doesn’t (and How you can Repair It)

How Fidelis Integrates Detection and Response for SQL-Based mostly Exploits

How India’s DPDP Act Impacts Digital Lending

Tags: CriticalCVE202525257flawFortinetFortiWebInjectionPatchReleasesSQL
Previous Post

New AI system uncovers hidden cell subtypes, boosts precision drugs | MIT Information

Next Post

Worker Retention: Find out how to Hold Your Greatest Individuals

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Your Wi-Fi Works however Your Web Doesn’t (and How you can Repair It)

by Md Sazzad Hossain
July 17, 2025
How Fidelis Integrates Detection and Response for SQL-Based mostly Exploits
Cyber Security

How Fidelis Integrates Detection and Response for SQL-Based mostly Exploits

by Md Sazzad Hossain
July 16, 2025
How India’s DPDP Act Impacts Digital Lending
Cyber Security

How India’s DPDP Act Impacts Digital Lending

by Md Sazzad Hossain
July 16, 2025
MITRE Launches New Framework to Sort out Crypto Dangers
Cyber Security

MITRE Launches New Framework to Sort out Crypto Dangers

by Md Sazzad Hossain
July 15, 2025
Anomaly detection betrayed us, so we gave it a brand new job – Sophos Information
Cyber Security

Anomaly detection betrayed us, so we gave it a brand new job – Sophos Information

by Md Sazzad Hossain
July 15, 2025
Next Post
Worker Retention: Find out how to Hold Your Greatest Individuals

Worker Retention: Find out how to Hold Your Greatest Individuals

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Optimize AI effectivity with small language fashions

Optimize AI effectivity with small language fashions

March 7, 2025
Luiz Domingos, CTO and Head of Massive Enterprise R&D at Mitel – Interview Sequence

Luiz Domingos, CTO and Head of Massive Enterprise R&D at Mitel – Interview Sequence

March 22, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know

Why Your Wi-Fi Works however Your Web Doesn’t (and How you can Repair It)

July 17, 2025
How an Unknown Chinese language Startup Stole the Limelight from the Stargate Venture – IT Connection

Google Cloud Focuses on Agentic AI Throughout UK Summit – IT Connection

July 17, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In