CVE-2022-35847: Code Injection
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35847?
CVE-2022-35847 is an improper neutralization of special elements used in a template engine vulnerability in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, and 6.4.0 through 6.4.4.
What is the severity of CVE-2022-35847?
The severity of CVE-2022-35847 is high with a severity value of 8.8.
How does CVE-2022-35847 impact FortiSOAR?
CVE-2022-35847 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
Which versions of FortiSOAR are affected by CVE-2022-35847?
FortiSOAR management interface versions 7.2.0, 7.0.0 through 7.0.3, and 6.4.0 through 6.4.4 are affected by CVE-2022-35847.
How can I fix CVE-2022-35847?
To fix CVE-2022-35847, Fortinet recommends upgrading to a fixed version when available. Please refer to the official Fortinet advisory for further instructions.