Path traversal in upload message

Summary

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.3 or above
FortiClientEMS 7.2 Not affected Not Applicable
FortiClientEMS 7.0 Not affected Not Applicable
FortiClientEMS Cloud 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.3 or above
FortiClientEMS Cloud 7.2 Not affected Not Applicable
FortiClientEMS Cloud 7.0 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Timeline

2025-05-13: Initial publication