CVE-2023-36548: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-36548?
CVE-2023-36548 is a vulnerability in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 that allows an attacker to execute unauthorized code or commands via specifically crafted HTTP GET request parameters.
How severe is CVE-2023-36548?
CVE-2023-36548 has a severity rating of 9.8 (Critical).
How does CVE-2023-36548 affect Fortinet FortiWLM?
CVE-2023-36548 affects Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4.
How can an attacker exploit CVE-2023-36548?
An attacker can exploit CVE-2023-36548 by sending specifically crafted HTTP GET request parameters to execute unauthorized code or commands.
Is there a fix for CVE-2023-36548?
Fortinet has released a fix for CVE-2023-36548. It is recommended to update to a patched version.