Directory Traversal

Summary

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.

Version Affected Solution
FortiWeb 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiWeb 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane of GMO Cybersecurity by Ierae working with Trend Micro Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Timeline

2025-04-08: Initial publication