An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website
2024-04-09T15:15:27.627
2025-01-17T17:08:31.843
Analyzed
CVSSv3.1: 9.6 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | < 7.0.11 | Yes |
Application | fortinet | forticlient | 7.0.3 | Yes |
Application | fortinet | forticlient | 7.0.4 | Yes |
Application | fortinet | forticlient | 7.2.0 | Yes |