A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
2023-02-16T19:15:12.403
2024-11-21T07:02:31.747
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | < 6.3.19 | Yes |
Application | fortinet | fortiweb | 6.4.0 | Yes |
Application | fortinet | fortiweb | 6.4.1 | Yes |
Application | fortinet | fortiweb | 6.4.2 | Yes |
Application | fortinet | fortiweb | 7.0.0 | Yes |
Application | fortinet | fortiweb | 7.0.1 | Yes |