CVE-2023-46713
published 2023-12-13CVE-2023-46713: An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.48%
38.0th percentile
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 6.2.0 – 6.2.8 | — |
| fortinet | fortiweb | 6.3.0 – 6.3.23 | — |
| fortinet | fortiweb | 7.0.0 – 7.0.9 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7...
vendor_fortinet·2023-12-13·CVSS 5.3
CVE-2023-46713 [MEDIUM] CWE-117 An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7...
FG-IR-23-256: An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7...
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
CVEs: CVE-2023-46713
CWEs: CWE-117
CVSS: 5.3 (medium)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-f8xj-xxr8-6q36: An improper output neutralization for logs in Fortinet FortiWeb 6
ghsa_unreviewed·2023-12-13
CVE-2023-46713 [MEDIUM] CWE-117 GHSA-f8xj-xxr8-6q36: An improper output neutralization for logs in Fortinet FortiWeb 6
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-13
Published