Lucene search

K
fortinetFortiGuard LabsFG-IR-22-131
HistoryFeb 16, 2023 - 12:00 a.m.

FortiWeb - Command injection in CLI backup functionality

2023-02-1600:00:00
FortiGuard Labs
www.fortiguard.com
25
fortiweb
command injection
cli backup
vulnerability
cwe-78
os command
bash commands
security

EPSS

0.001

Percentile

41.7%

An improper neutralization of special elements used in an OS command (β€˜OS Command Injection’) vulnerability [CWE-78] in FortiWeb may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters.

EPSS

0.001

Percentile

41.7%

Related for FG-IR-22-131