OS Command Injection Vulnerability in Fortinet FortiWLM
CVE-2023-36547
9.6CRITICAL
What is CVE-2023-36547?
An OS command injection vulnerability in Fortinet FortiWLM versions 8.6.0 to 8.6.5 and 8.5.0 to 8.5.4 enables attackers to execute unauthorized commands on the system. This occurs due to insufficient neutralization of special elements in HTTP GET request parameters, allowing crafted requests to manipulate the command execution process.
Affected Version(s)
FortiWLM 8.6.0 <= 8.6.5
FortiWLM 8.5.0 <= 8.5.4