Lucene search

K
fortinetFortiGuard LabsFG-IR-22-306
HistorySep 06, 2022 - 12:00 a.m.

FortiSOAR - Server-Side Template Injection in Playbook component

2022-09-0600:00:00
FortiGuard Labs
www.fortiguard.com
14
fortisoar
server-side template injection
cwe-1336
management interface
remote attacker
authenticated attacker
arbitrary code
crafted payload

EPSS

0.001

Percentile

43.2%

An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.

EPSS

0.001

Percentile

43.2%

Related for FG-IR-22-306