cbcvebase.
CVE-2023-47542
published 2024-04-09

CVE-2023-47542: A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and…

PriorityP434medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.27%
18.7th percentile
A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortimanager
fortinetfortimanager>= 7.0.0 < 7.0.117.0.11
fortinetfortimanager7.0.0 – 7.0.10
fortinetfortimanager>= 7.2.0 < 7.2.57.2.5
fortinetfortimanager7.2.0 – 7.2.4
fortinetfortimanager>= 7.4.0 < 7.4.27.4.2
fortinetfortimanager7.4.0 – 7.4.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.