PSIRT Advisories
FortiWeb - Path traversal in API controller
Summary
A relative path traversal vulnerability [CWE-23] in the API of FortiWeb may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Products
FortiWeb version 7.0.0 through 7.0.2FortiWeb version 6.3.6 through 6.3.20
FortiWeb 6.4 all versions
Solutions
Please upgrade to FortiWeb version 7.0.3 or abovePlease upgrade to FortiWeb version 6.3.21 or above