CVE-2023-23779: OS Command Injection
Published Feb 16, 2023
·Updated
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.
Affected Software
6 affected components
Fortinet FortiWeb>=6.3.6<=6.3.19
Fortinet FortiWeb=6.4.0
Fortinet FortiWeb=6.4.1
Fortinet FortiWeb=6.4.2
Fortinet FortiWeb=7.0.0
Fortinet FortiWeb=7.0.1
Remediation
Information
Please upgrade to FortiWeb version 7.0.2 or above
Please upgrade to FortiWeb version 6.3.20 or above
Event History
Feb 16, 2023
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-23779.
2
What is the severity of CVE-2023-23779?
The severity of CVE-2023-23779 is high with a CVSS score of 8.8.
3
Which versions of FortiWeb are affected by CVE-2023-23779?
FortiWeb version 7.0.1 and below, 6.4 all versions, and version 6.3.19 and below are affected by CVE-2023-23779.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-78.
5
How can an attacker exploit CVE-2023-23779?
An authenticated attacker can execute unauthorized code or commands via crafted parameters to exploit CVE-2023-23779.