Authenticated command injection vulnerability

Summary

Multiple Improper neutralization of special elements used in an os command vulnerabilities [CWE-78] in FortiWLM may allow a remote authenticated attacker with low privilege to execute unauthorized commands via specifically crafted http get request parameters.

Version Affected Solution
FortiWLM 8.6 8.6.0 through 8.6.5 Upgrade to 8.6.6 or above
FortiWLM 8.5 8.5.0 through 8.5.4 Upgrade to 8.5.5 or above

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2023-10-10: Initial publication