CVE-2021-41026

A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:25

Type Values Removed Values Added
References () https://fortiguard.com/advisory/FG-IR-21-156 - Vendor Advisory () https://fortiguard.com/advisory/FG-IR-21-156 - Vendor Advisory

Information

Published : 2022-04-06 16:15

Updated : 2024-11-21 06:25


NVD link : CVE-2021-41026

Mitre link : CVE-2021-41026

CVE.ORG link : CVE-2021-41026


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')