Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.
Problem types
Execute unauthorized code or commands
Product status
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.0
References
fortiguard.fortinet.com/psirt/FG-IR-24-473