Path traversal via browse report CGI component

Summary

A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.

Affected Products

At least
FortiWeb 7.2 all versions are not affected
FortiWeb version 7.0.0 through 7.0.1
FortiWeb version 6.4.0 through 6.4.2
FortiWeb 6.3 all versions
FortiWeb version 6.2.3 through 6.2.8
FortiWeb 6.1 all versions are not affected

Solutions

Please upgrade to FortiWeb version 7.0.2 or above

Timeline

2023-02-16: Initial publication