Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortisoar  >> 7.0.0  Security Vulnerabilities
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
CVSS Score
6.3
EPSS Score
0.003
Published
2022-09-06
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-09-06
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
CVSS Score
7.5
EPSS Score
0.018
Published
2022-05-04


Contact Us

Shodan ® - All rights reserved