Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jc24-hjq6-4g6f

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

EPSS

Процентиль: 97%
0.35252
Средний

8.1 High

CVSS3

Дефекты

CWE-233

Связанные уязвимости

CVSS3: 8.1
nvd
6 месяцев назад

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

CVSS3: 8.1
fstec
6 месяцев назад

Уязвимость межсетевого экрана веб-приложений FortiWeb, связанная с ошибками обработки параметров, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 97%
0.35252
Средний

8.1 High

CVSS3

Дефекты

CWE-233