Path traversal via browse report CGI component
Summary
A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.
Affected Products
At leastFortiWeb 7.2 all versions are not affected
FortiWeb version 7.0.0 through 7.0.1
FortiWeb version 6.4.0 through 6.4.2
FortiWeb 6.3 all versions
FortiWeb version 6.2.3 through 6.2.8
FortiWeb 6.1 all versions are not affected
Solutions
Please upgrade to FortiWeb version 7.0.2 or above