A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests.
2025-03-11T15:15:44.010
2025-07-24T18:47:34.860
Analyzed
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | < 7.4.6 | Yes |
Application | fortinet | fortiweb | 7.6.0 | Yes |