Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jc24-hjq6-4g6f

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

EPSS

Процентиль: 95%
0.09825
Низкий

8.1 High

CVSS3

Дефекты

CWE-233

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 года назад

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

CVSS3: 8.1
fstec
около 1 года назад

Уязвимость межсетевого экрана веб-приложений FortiWeb, связанная с ошибками обработки параметров, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 95%
0.09825
Низкий

8.1 High

CVSS3

Дефекты

CWE-233