FG-IR-25-910: Path confusion vulnerability in GUI
A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. Fortinet has observed this to be exploited in the wild FortiAppSec Cloud is NOT impacted by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-910?
The severity of FG-IR-25-910 is critical due to its potential for unauthorized administrative command execution.
How do I fix FG-IR-25-910?
To fix FG-IR-25-910, upgrade FortiWeb to version 8.0.2 or later for 8.x versions, 7.6.5 or later for 7.6.x versions, 7.4.10 or later for 7.4.x versions, 7.2.12 or later for 7.2.x versions, and 7.0.12 or later for 7.0.x versions.
What types of systems are affected by FG-IR-25-910?
FG-IR-25-910 affects FortiWeb systems running specific vulnerable versions across various major release lines.
Can FG-IR-25-910 be exploited remotely?
Yes, FG-IR-25-910 can be remotely exploited by unauthenticated attackers through specially crafted HTTP or HTTPS requests.
Has FG-IR-25-910 been actively exploited in the wild?
Yes, active exploitation of FG-IR-25-910 has been observed by Fortinet.