An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
2022-09-06T18:15:15.763
2024-11-21T07:11:48.787
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | ≤ 6.4.4 | Yes |
Application | fortinet | fortisoar | ≤ 7.0.3 | Yes |
Application | fortinet | fortisoar | 7.2.0 | Yes |