FG-IR-23-189: Path traversal via unrestricted file upload
A relative path traversal [CWE-23] vulnerability in FortiManager and FortiAnalyzer may allow a remote attacker with low privileges to execute unauthorized code via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-189?
The severity of FG-IR-23-189 is classified as critical due to its potential for unauthorized code execution.
How do I fix FG-IR-23-189?
To fix FG-IR-23-189, upgrade FortiManager or FortiAnalyzer to the recommended versions specified in the advisory.
Which versions are affected by FG-IR-23-189?
FG-IR-23-189 affects multiple versions of FortiManager and FortiAnalyzer prior to their respective remedial releases.
Who is vulnerable to FG-IR-23-189?
Remote attackers with low privileges can exploit FG-IR-23-189 if they have access to the affected Fortinet products.
What type of vulnerability is FG-IR-23-189?
FG-IR-23-189 is a relative path traversal vulnerability, which allows for unauthorized code execution via crafted HTTP requests.