Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30303


AnĀ improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests.


Published

2023-02-16T19:15:12.467

Last Modified

2024-11-21T07:02:32.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiweb < 6.3.20 Yes
Application fortinet fortiweb 6.4.0 Yes
Application fortinet fortiweb 6.4.1 Yes
Application fortinet fortiweb 6.4.2 Yes
Application fortinet fortiweb 7.0.0 Yes
Application fortinet fortiweb 7.0.1 Yes

References