Fortinet.FortiWeb.admin.Path.Traversal

description-logoDescription

This indicates an attack attempt to exploit a Path Traversal Vulnerability in Fortinet FortiWeb.
The vulnerability is due to insufficient sanitizing of user-supplied inputs. A remote attacker can exploit this to read or write arbitrary files in a crafted request. Successful exploitation of this vulnerability could lead to arbitrary code execution.

affected-products-logoAffected Products

Fortinet FortiWeb 7.0.x prior to 7.0.12
Fortinet FortiWeb 7.2.x prior to 7.2.12
Fortinet FortiWeb 7.4.x prior to 7.4.10
Fortinet FortiWeb 7.6.x prior to 7.6.5
Fortinet FortiWeb 8.0.x prior to 8.0.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://fortiguard.fortinet.com/psirt/FG-IR-25-910

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-12-09 35.130
Modified
Default_action:pass:drop
2025-11-20 34.122
New