Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiweb  >> 7.4.8  Security Vulnerabilities
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
CVSS Score
4.9
EPSS Score
0.001
Published
2025-09-09
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
CVSS Score
6.4
EPSS Score
0.0
Published
2025-08-12
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
CVSS Score
6.7
EPSS Score
0.0
Published
2025-08-12
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
CVSS Score
2.7
EPSS Score
0.001
Published
2025-01-14


Contact Us

Shodan ® - All rights reserved