Vulnerability Details CVE-2022-29062
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.7%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2022-29062
-
cpe:2.3:a:fortinet:fortisoar:7.0.0
-
cpe:2.3:a:fortinet:fortisoar:7.0.1
-
cpe:2.3:a:fortinet:fortisoar:7.0.2
-
cpe:2.3:a:fortinet:fortisoar:7.2.0