Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
2022-09-06T18:15:13.100
2024-11-21T06:58:25.937
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | < 7.0.3 | Yes |
Application | fortinet | fortisoar | 7.2.0 | Yes |