PT-2023-1500 · Fortinet · Fortiweb

CVE-2022-30300

·

Publicado

2023-02-16

·

Atualizado

2023-02-24

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.3.6 through 6.3.18 FortiWeb versions 6.4 FortiWeb versions 7.0.0 through 7.0.1
Description The issue is related to a relative path traversal vulnerability in FortiWeb, which may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. This is due to incorrect restriction of the directory path name with limited access.
Recommendations For FortiWeb versions 6.3.6 through 6.3.18, update to a version outside of this range to resolve the issue. For FortiWeb versions 6.4, update to a version outside of this range to resolve the issue. For FortiWeb versions 7.0.0 through 7.0.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to specifically crafted HTTP GET requests until a patch is available.

Correção

Relative Path Traversal

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00922
CVE-2022-30300

Produtos afetados

Fortiweb