A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.
2024-04-09T15:15:28.207
2025-01-17T17:11:28.947
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortimanager | < 7.0.11 | Yes |
Application | fortinet | fortimanager | < 7.2.5 | Yes |
Application | fortinet | fortimanager | < 7.4.2 | Yes |