Lucene search

K
fortinetFortiGuard LabsFG-IR-21-128
HistoryMar 01, 2022 - 12:00 a.m.

FortiWLM - command Injection in script handlers

2022-03-0100:00:00
FortiGuard Labs
www.fortiguard.com
18
fortiwlm
command injection
os command injection
cwe-78
vulnerability
authenticated attacker
shell commands

EPSS

0.001

Percentile

48.5%

An improper neutralization of special elements used in an OS command (‘OS Command Injection’) [CWE-78] vulnerability in FortiWLM may allow an authenticated attacker to execute arbitrary shell commands via crafted HTTP requests to the alarm dashboard and controller config handlers.

EPSS

0.001

Percentile

48.5%

Related for FG-IR-21-128