Description


An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

Related CPE's


a

fortinet

fortivoice

2

Weaknesses



CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-13T17:15:57.940Z

34 hours ago

Last modified

2026-01-14T21:34:22.663Z

6 hours ago