ZeroHour

CVE-2023-47542

CVSS 3.1
6.7 medium
EPSS
<1%p19
Published
()
Modified
Description

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.

Vendors
fortinet
Products
fortimanager
Weakness
CWE-1336, CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.