Directory Traversal Arbitrary File Write Vulnerability

Summary

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb API endpoint may allow an authenticated attacker with admin privileges to access and modify the filesystem.

Version Affected Solution
FortiWeb 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiWeb 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane of GMO Cybersecurity by Ierae working with Trend Micro Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Timeline

2025-03-11: Initial publication