ZeroHour

CVE-2020-29018

CVSS 3.1
8.8 high
EPSS
2%p80
Published
()
Modified
Description

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

Vendors
fortinet
Products
fortiweb
Weakness
CWE-134
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news