CVE-2021-41026

A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
References
Link Resource
https://fortiguard.com/advisory/FG-IR-21-156 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-04-06 16:15

Updated : 2022-04-13 18:06


NVD link : CVE-2021-41026

Mitre link : CVE-2021-41026

CVE.ORG link : CVE-2021-41026


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')