<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Path traversal in API handler</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-136</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-02-16T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-02-16T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-02-16T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiWeb 7.2 all versions are not affectedFortiWeb version 7.0.0 through 7.0.1FortiWeb version 6.4.0 through 6.4.2FortiWeb version 6.3.6 through 6.3.18FortiWeb 6.2 all versions are not affectedFortiWeb 6.1 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Upgrade FortiWeb to version 7.0.2 and above.Upgrade FortiWeb to version 6.3.19 and above.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Théo Leleu of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiWeb" Type="Product Name">
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.1">FortiWeb 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.0">FortiWeb 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.4.2">FortiWeb 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.4.1">FortiWeb 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.4.0">FortiWeb 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.3.18" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.18">FortiWeb 6.3.18</FullProductName>
                </Branch>
                <Branch Name="6.3.17" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.17">FortiWeb 6.3.17</FullProductName>
                </Branch>
                <Branch Name="6.3.16" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.16">FortiWeb 6.3.16</FullProductName>
                </Branch>
                <Branch Name="6.3.15" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.15">FortiWeb 6.3.15</FullProductName>
                </Branch>
                <Branch Name="6.3.14" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.14">FortiWeb 6.3.14</FullProductName>
                </Branch>
                <Branch Name="6.3.13" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.13">FortiWeb 6.3.13</FullProductName>
                </Branch>
                <Branch Name="6.3.12" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.12">FortiWeb 6.3.12</FullProductName>
                </Branch>
                <Branch Name="6.3.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.11">FortiWeb 6.3.11</FullProductName>
                </Branch>
                <Branch Name="6.3.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.10">FortiWeb 6.3.10</FullProductName>
                </Branch>
                <Branch Name="6.3.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.9">FortiWeb 6.3.9</FullProductName>
                </Branch>
                <Branch Name="6.3.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.8">FortiWeb 6.3.8</FullProductName>
                </Branch>
                <Branch Name="6.3.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.7">FortiWeb 6.3.7</FullProductName>
                </Branch>
                <Branch Name="6.3.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-6.3.6">FortiWeb 6.3.6</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Path traversal in API handler</Title>
        <cvrf:CVE>CVE-2022-30300</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiWeb-7.0.1</ProductID>
                <ProductID>FortiWeb-7.0.0</ProductID>
                <ProductID>FortiWeb-6.4.2</ProductID>
                <ProductID>FortiWeb-6.4.1</ProductID>
                <ProductID>FortiWeb-6.4.0</ProductID>
                <ProductID>FortiWeb-6.3.18</ProductID>
                <ProductID>FortiWeb-6.3.17</ProductID>
                <ProductID>FortiWeb-6.3.16</ProductID>
                <ProductID>FortiWeb-6.3.15</ProductID>
                <ProductID>FortiWeb-6.3.14</ProductID>
                <ProductID>FortiWeb-6.3.13</ProductID>
                <ProductID>FortiWeb-6.3.12</ProductID>
                <ProductID>FortiWeb-6.3.11</ProductID>
                <ProductID>FortiWeb-6.3.10</ProductID>
                <ProductID>FortiWeb-6.3.9</ProductID>
                <ProductID>FortiWeb-6.3.8</ProductID>
                <ProductID>FortiWeb-6.3.7</ProductID>
                <ProductID>FortiWeb-6.3.6</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.2</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-136</URL>
                <Description>Path traversal in API handler</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>