CVE-2022-30299Relative Path Traversal in Fortinet Fortiweb

Severity
4.3MEDIUMNVD
CNA5.3
EPSS
0.5%
top 33.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16

Description

A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the underlying file system via specially crafted web requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDfortinet/fortiweb6.3.06.3.20+8
CVEListV5fortinet/fortiweb7.0.07.0.1+5

Patches

🔴Vulnerability Details

2
CVEList
CVE-2022-30299: A path traversal vulnerability [CWE-23] in the API of FortiWeb 72023-02-16
GHSA
GHSA-37g8-cx8g-rxvj: A path traversal vulnerability [CWE-23] in the API of FortiWeb 72023-02-16

📋Vendor Advisories

1
Fortinet
A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versio...2023-02-16
CVE-2022-30299 — Relative Path Traversal in Fortinet | cvebase