cbcvebase.
CVE-2024-52964
published 2025-08-12

CVE-2024-52964: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1…

medium6.5CVSS 3.1
AVNACLPRHUINSUCNIHAH
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

Affected

16 ranges
VendorProductVersion rangeFixed in
fortinetfortimanager
fortinetfortimanager>= 6.2.0 < 7.0.147.0.14
fortinetfortimanager6.2.0 – 6.2.13
fortinetfortimanager6.4.0 – 6.4.15
fortinetfortimanager7.0.0 – 7.0.13
fortinetfortimanager>= 7.2.0 < 7.2.107.2.10
fortinetfortimanager7.2.0 – 7.2.9
fortinetfortimanager>= 7.4.0 < 7.4.67.4.6
fortinetfortimanager7.4.0 – 7.4.5
fortinetfortimanager>= 7.6.0 < 7.6.27.6.2
fortinetfortimanager7.6.0 – 7.6.1
fortinetfortimanager_cloud6.4.1 – 7.0.13
fortinetfortimanager_cloud>= 7.2.1 < 7.2.107.2.10
fortinetfortimanager_cloud>= 7.4.1 < 7.4.67.4.6
fortinetfortimanagercloud
fortinetfortinet