VYPR
Medium severity4.9NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2023-23778

CVE-2023-23778

Description

A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.

Affected products

9
  • Fortinet/Fortiweb8 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.2.3,<=6.2.7
    • cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
    • (no CPE)range: <=7.0.1, all versions of 6.4, 6.3, 6.2
    • (no CPE)range: 7.0.0
  • FortiWeb/FortiWebllm-create
    Range: <=7.0.1, all versions of 6.4, 6.3, 6.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.