An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPs requests.
2025-01-14T14:15:29.360
2025-01-21T21:03:02.247
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortianalyzer | < 7.2.6 | Yes |
Application | fortinet | fortianalyzer | < 7.4.3 | Yes |
Application | fortinet | fortimanager | < 7.2.6 | Yes |
Application | fortinet | fortimanager | < 7.4.3 | Yes |