CVE-2023-23784: Path Traversal
A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet FortiWeb vulnerability?
The vulnerability ID for this Fortinet FortiWeb vulnerability is CVE-2023-23784.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Fortinet FortiWeb versions 7.0.0 through 7.0.2, FortiWeb versions 6.3.6 through 6.3.20, and FortiWeb 6.4 all versions.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using specially crafted web requests to perform relative path traversal and gain access to sensitive information.
What is the severity of this vulnerability?
The severity of this vulnerability is medium, with a CVSS score of 6.5.
Is there a patch or fix available for this vulnerability?
Yes, Fortinet has released patches to address this vulnerability. It is recommended to update to the latest version of FortiWeb to mitigate the risk.