First published: Mon Apr 07 2025(Updated: )
This vulnerability allows remote attackers to create arbitrary XML schema files on affected installations of Fortinet FortiWeb. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-55597.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-25-202 is rated at 5.5 on the CVSS scale.
To fix ZDI-25-202, apply the latest security patches provided by Fortinet for FortiWeb.
Remote attackers with authentication can exploit ZDI-25-202 to create arbitrary XML schema files.
The potential impact of ZDI-25-202 includes unauthorized modifications to XML schema files, which can affect application functionality.
Yes, user authentication is required to exploit the vulnerability ZDI-25-202.