A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
References
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-051 | Vendor Advisory |
Configurations
History
18 Apr 2023, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://fortiguard.com/psirt/FG-IR-23-051 - Vendor Advisory | |
| CWE | NVD-CWE-Other | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Fortinet
Fortinet fortisoar |
|
| CPE | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* |
11 Apr 2023, 17:21
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-04-11 17:15
Updated : 2023-11-07 04:10
NVD link : CVE-2023-27995
Mitre link : CVE-2023-27995
JSON object : View
Products Affected
fortinet
- fortisoar
CWE
