PT-2025-11595 · Fortisoar · Fortisoar Connector

Published

2025-03-18

·

Updated

2025-03-18

·

CVE-2024-21760

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiSOAR Connector FortiSOAR versions 6.4 through 7.4
Description An improper control of generation of code, also known as 'Code Injection', may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.
Recommendations For FortiSOAR Connector FortiSOAR versions 6.4 through 7.4, consider disabling the execution of playbook code snippets until a patch is available to prevent potential code injection attacks.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-21760

Affected Products

Fortisoar Connector