Lucene search

K
fortinetFortiGuard LabsFG-IR-21-180
HistoryFeb 01, 2022 - 12:00 a.m.

FortiWeb - OS command injection due to direct input interpolation in API controllers

2022-02-0100:00:00
FortiGuard Labs
www.fortiguard.com
11
fortiweb
command injection
api
cwe-78
http requests

EPSS

0.001

Percentile

48.5%

An improper neutralization of special elements used in an OS command (‘OS Command Injection’) vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute arbitrary code or commands via crafted HTTP requests to ApplicationDelivery, JsonProtection and WebProtection controllers.

EPSS

0.001

Percentile

48.5%

Related for FG-IR-21-180