Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiVoice version 7.0.1 or above Please upgrade to FortiVoice version 6.4.8 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41785 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-219 |
|
History
Thu, 17 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-04-17T15:45:35.341Z
Reserved: 2023-07-11T08:16:54.092Z
Link: CVE-2023-37932
Updated: 2024-08-02T17:23:27.749Z
Status : Modified
Published: 2024-01-10T18:15:45.570
Modified: 2024-11-21T08:12:29.797
Link: CVE-2023-37932
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD