Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqxp-5rvv-7f48

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

EPSS

Процентиль: 94%
0.07492
Низкий

8.1 High

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 8.1
nvd
8 месяцев назад

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

CVSS3: 8.1
fstec
10 месяцев назад

Уязвимость метода ApacheCookie_parse межсетевого экрана веб-приложений FortiWeb, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольные команды

EPSS

Процентиль: 94%
0.07492
Низкий

8.1 High

CVSS3

Дефекты

CWE-565