An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters.
2023-07-11T09:15:09.460
2024-11-21T07:46:48.640
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | ≤ 6.3.18 | Yes |
Application | fortinet | fortiweb | ≤ 6.4.3 | Yes |
Application | fortinet | fortiweb | 7.0.0 | Yes |
Application | fortinet | fortiweb | 7.0.1 | Yes |