A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-254 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fortinet

Published: 2023-03-07T16:04:38.353Z

Updated: 2023-03-07T16:04:38.353Z

Reserved: 2022-09-05T13:11:35.553Z


Link: CVE-2022-39951

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-07T17:15:11.877

Modified: 2023-11-07T03:50:41.147


Link: CVE-2022-39951

JSON object: View

cve-icon Redhat Information

No data.

CWE