CVE-2023-27995
published 2023-04-11CVE-2023-27995: A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.14%
62.9th percentile
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | >= 7.3.0 < 7.3.2 | 7.3.2 |
| fortinet | fortisoar | 7.3.0 – 7.3.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 throug...
vendor_fortinet·2023-04-11·CVSS 7.2
CVE-2023-27995 [HIGH] CWE-1336 A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 throug...
FG-IR-23-051: A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 throug...
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
CVEs: CVE-2023-27995
CWEs: CWE-1336
CVSS: 7.2 (high)
Affected products: FortiSOAR, Fortinet
GHSA
GHSA-vx6h-vg27-fxxc: A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7
ghsa_unreviewed·2023-04-11
CVE-2023-27995 [HIGH] CWE-1336 GHSA-vx6h-vg27-fxxc: A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-11
Published