Unauthenticated command injection vulnerability
Summary
Multiple improper neutralization of special elements used in an os command ("OS command injection") vulnerabilities [CWE-78] in FortiWLM may allow a remote unauthenticated attacker to execute unauthorized commands via specifically crafted http get request parameters.
Version | Affected | Solution |
---|---|---|
FortiWLM 8.6 | 8.6.0 through 8.6.5 | Upgrade to 8.6.6 or above |
FortiWLM 8.5 | 8.5.0 through 8.5.4 | Upgrade to 8.5.5 or above |
Acknowledgement
Fortinet is pleased to thank security researchers Zach Hanley (@hacks_zach) of Horizon3.ai for discovering and reporting this vulnerability under responsible disclosure.Timeline
2023-10-10: Initial publication