A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.
2021-10-06T10:15:07.623
2024-11-21T05:06:30.020
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient_endpoint_management_server | < 6.2.9 | Yes |
Application | fortinet | forticlient_endpoint_management_server | < 6.4.2 | Yes |