An improper neutralization of special elements used in an SQL command in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. The vulnerability can be further escalated to a Remote Code Execution. The IONIX research team validated the impact through successful exploit reproduction, as detailed in this advisory.
References:

