Multiple Path Traversal Vulnerabilities in FortiDeceptor Management Interface
CVE-2022-30302
6.5MEDIUM
What is CVE-2022-30302?
FortiDeceptor contains multiple vulnerabilities allowing remote and authenticated attackers to exploit relative path traversal. This can enable unauthorized access to sensitive files and the ability to remove arbitrary files from the system. Attackers may leverage specially crafted web requests to manipulate file paths, posing significant risks to system integrity and data confidentiality.
Affected Version(s)
Fortinet FortiDeceptor FortiDeceptor 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1