CVE-2025-64156

Source
https://cve.org/CVERecord?id=CVE-2025-64156
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64156.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64156
Published
2025-12-09T18:16:05.070Z
Modified
2026-03-13T03:38:22.271714Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.0.0"
            },
            {
                "last_affected": "6.0.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.4.0"
            },
            {
                "last_affected": "6.4.11"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.0.0"
            },
            {
                "last_affected": "7.0.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.0"
            },
            {
                "last_affected": "7.2.1"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64156.json"