First published: Tue Apr 08 2025(Updated: )
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=7.6.0<=7.6.2 | |
Fortinet FortiWeb | >=7.4.0<=7.4.6 | |
Fortinet FortiWeb | >=7.2 | |
Fortinet FortiWeb | >=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-474 is considered high due to the potential for unauthorized filesystem access.
To fix FG-IR-24-474, upgrade FortiWeb to version 7.6.3 or later, or 7.4.7 or later, depending on your current version.
FG-IR-24-474 affects administrators using FortiWeb versions 7.6.2 and earlier for 7.6, 7.4.6 and earlier for 7.4, and all versions from 7.2 and 7.0.
FG-IR-24-474 is an improper limitation of a pathname to a restricted directory, commonly known as a path traversal vulnerability.
Yes, FG-IR-24-474 can potentially be exploited remotely by authenticated administrators through crafted requests.