Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9v3-m3cf-6942

Опубликовано: 13 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.

EPSS

Процентиль: 84%
0.02073
Низкий

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость инструмента аналитики и управления безопасностью Fortinet FortiPortal, связанная с отсутствием мер по очистке входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 84%
0.02073
Низкий

8.8 High

CVSS3

Дефекты

CWE-77