Path traversal in API handler

Summary

A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.

Affected Products

FortiWeb version 7.0.0 through 7.0.1
FortiWeb version 6.4.0 through 6.4.2
FortiWeb version 6.3.6 through 6.3.18

Solutions

Upgrade FortiWeb to version 7.0.2 and above.
Upgrade FortiWeb to version 6.3.19 and above.

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2023-02-16: Initial publication