CVE-2024-33502 Information
Jan 15, 2025
cve
Description
An improper limitation of a pathname to a restricted directory (‘path traversal’) in Fortinet FortiManager FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPs requests.
Reference
https://fortiguard.fortinet.com/psirt/FG-IR-24-143
Share on: