An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
2022-09-09T07:15:07.313
2024-11-21T06:58:25.810
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | ≤ 6.4.4 | Yes |
Application | fortinet | fortisoar | < 7.0.3 | Yes |
Application | fortinet | fortisoar | 7.2.0 | Yes |