A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
2025-01-14T14:15:29.200
2025-03-19T15:46:05.970
Analyzed
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortimanager | < 7.2.6 | Yes |
Application | fortinet | fortimanager | < 7.4.3 | Yes |