Improper Handling of Inputs in Fortinet FortiWeb Affects Multiple Versions
CVE-2023-42784
5.5MEDIUM
Summary
An improper handling of syntactically invalid structures in Fortinet FortiWeb versions 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10 can allow attackers to craft malicious HTTP/S requests that lead to unauthorized execution of code or commands. This vulnerability exposes systems to additional security threats, as it enables the exploitation of weak input validation mechanisms.
Affected Version(s)
FortiWeb 7.4.0 <= 7.4.7
FortiWeb 7.2.0 <= 7.2.10
FortiWeb 7.0.0 <= 7.0.10
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved