An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
2024-01-10T18:15:45.570
2024-11-21T08:12:29.797
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortivoice | ≤ 6.0.12 | Yes |
Application | fortinet | fortivoice | < 6.4.8 | Yes |
Application | fortinet | fortivoice | 7.0.0 | Yes |