Description
An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiWeb version 7.0.2 or above Please upgrade to FortiWeb version 6.3.20 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52254 | An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-163 |
|
History
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-23T14:50:25.965Z
Reserved: 2022-05-06T12:09:27.623Z
Link: CVE-2022-30303
Updated: 2024-08-03T06:48:35.825Z
Status : Modified
Published: 2023-02-16T19:15:12.467
Modified: 2024-11-21T07:02:32.090
Link: CVE-2022-30303
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD