Multiple authenticated OS Command Injections via API
Summary
An OS command injection vulnerabtility [CWE-78] in FortiExtender API may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.
| Version | Affected | Solution |
|---|---|---|
| FortiExtender 7.6 | 7.6.0 through 7.6.3 | Upgrade to 7.6.4 or above |
| FortiExtender 7.4 | 7.4.0 through 7.4.7 | Upgrade to 7.4.8 or above |
| FortiExtender 7.2 | 7.2 all versions | Migrate to a fixed release |
| FortiExtender 7.0 | 7.0 all versions | Migrate to a fixed release |