FG-IR-26-115: Arbitrary directory delete on vmimages delete feature
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-115?
The FG-IR-26-115 vulnerability is classified as a high severity issue due to its potential for arbitrary directory deletion.
How do I fix FG-IR-26-115?
To address the FG-IR-26-115 vulnerability, upgrade FortiSandbox versions below 5.0.6 or 4.4.9 to the respective patched versions.
Which Fortinet products are affected by FG-IR-26-115?
The FG-IR-26-115 vulnerability affects FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, specifically certain versions within each product line.
Can an unprivileged user exploit FG-IR-26-115?
No, FG-IR-26-115 requires a privileged attacker with super-admin profile to exploit this vulnerability.
What type of vulnerability is FG-IR-26-115?
FG-IR-26-115 is categorized as a Path Traversal vulnerability, allowing unauthorized access to restricted directories.