Path traversal in policy scripting

Summary

A Relative Path Traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.

Version Affected Solution
FortiWeb 8.0 Not affected Not Applicable
FortiWeb 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above
FortiWeb 7.4 7.4.0 through 7.4.8 Upgrade to 7.4.9 or above
FortiWeb 7.2 7.2.0 through 7.2.11 Upgrade to upcoming version 7.2.12 or above
FortiWeb 7.0 7.0.2 through 7.0.11 Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Jason McFadyen from Trend Research of Trend Micro for reporting this vulnerability under responsible disclosure.

Timeline

2025-09-09: Initial publication