A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-136 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-16 11:15
Updated : 2023-02-24 15:40
NVD link : CVE-2022-30300
Mitre link : CVE-2022-30300
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
fortinet
- fortiweb


