PT-2025-10784 · Fortinet · Fortiweb

Published

2025-03-11

·

Updated

2025-04-07

·

CVE-2024-55597

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: Fortinet FortiWeb versions 7.0.0 through 7.6.0
Description: The issue is related to an improper limitation of a pathname to a restricted directory, also known as 'path traversal'. This allows an attacker to execute unauthorized code or commands via crafted requests.
Recommendations: For Fortinet FortiWeb versions 7.0.0 through 7.6.0, update to a version that fixes the 'path traversal' issue to prevent unauthorized code execution.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-03650
CVE-2024-55597
ZDI-25-202

Affected Products

Fortiweb