Path Traversal Vulnerability in Fortinet FortiManager
CVE-2024-52964
6.5MEDIUM
What is CVE-2024-52964?
An improper limitation of a pathname to a restricted directory vulnerability in Fortinet FortiManager can allow authenticated remote attackers to overwrite arbitrary files. This issue affects multiple versions of FortiManager and FortiManager Cloud, which could expose sensitive data and severely compromise system integrity. Attackers may exploit this flaw through crafted FGFM requests, leading to unauthorized access and manipulation of files.
Affected Version(s)
FortiManager 7.6.0 <= 7.6.1
FortiManager 7.4.0 <= 7.4.5
FortiManager 7.2.0 <= 7.2.9