Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
Problem types
Execute unauthorized code or commands
Product status
7.6.0
7.4.1
References
fortiguard.fortinet.com/psirt/FG-IR-25-253