Description
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
Related CPE's
a
fortinet
fortiwebmanager
5
References
https://fortiguard.fortinet.com/psirt/FG-IR-23-222
Vendor Advisory
https://fortiguard.fortinet.com/psirt/FG-IR-23-222
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2024-06-03T10:15:13.523Z
2 years agoLast modified
2026-07-08T14:16:51.287Z
2 months ago