A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
2025-09-09T14:15:46.363
2025-09-10T15:14:32.080
Analyzed
CVSSv3.1: 4.9 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | fortinet | fortiweb | < 7.2.12 | Yes |
| Application | fortinet | fortiweb | < 7.4.9 | Yes |
| Application | fortinet | fortiweb | < 7.6.5 | Yes |