Impact
The vulnerability is caused by an incomplete list of disallowed inputs in Fortinet FortiWeb. This defect allows an attacker to send inputs that are not properly rejected, thereby bypassing the intended access controls. The weakness can be classified as a case of improper handling of input data (CWE‑184) and may enable an attacker to gain unauthorized access to protected resources or administrative functions.
Affected Systems
Affected vendors include Fortinet. Product impact spans FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, all 7.4 releases, all 7.2 releases, and all 7.0 releases. Additionally, a range of FortiOS firmware versions (from 6.4.0 to 7.6.7) are listed as potentially vulnerable, although the description focuses on FortiWeb.
Risk and Exploitability
The CVSS score of 4.8 positions this vulnerability in the medium severity range. EPSS is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending crafted HTTP requests that rely on the missing disallowed input checks; thus the compromise would be remote and network-facing. Given the lack of known exploits and the moderate CVSS, the risk is significant enough to warrant prompt action, but the likelihood is not high unless the attacker is specifically targeting FortiWeb deployments.
OpenCVE Enrichment