A use of externally-controlled format string in Fortinet...
High severity
Unreviewed
Published
Feb 16, 2023
to the GitHub Advisory Database
•
Updated Mar 4, 2023
Description
Published by the National Vulnerability Database
Feb 16, 2023
Published to the GitHub Advisory Database
Feb 16, 2023
Last updated
Mar 4, 2023
A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted command arguments.
References