CVE-2023-27995
published 2023-04-11CVE-2023-27995: A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | >= 7.3.0 < 7.3.2 | 7.3.2 |
| fortinet | fortisoar | 7.3.0 – 7.3.1 | — |