Medium severity6.5NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026
CVE-2022-30300
CVE-2022-30300
Description
A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
Affected products
8cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.6,<6.3.19
- cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
- (no CPE)range: 7.0.0-7.0.1, 6.3.6-6.3.18, 6.4
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-136nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.