CVE-2024-48892

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoar:7.6.0:*:*:*:*:*:*:*

History

14 Aug 2025, 01:14

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortisoar:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-421 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-421 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Fortinet fortisoar
Fortinet

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-14 01:14


NVD link : CVE-2024-48892

Mitre link : CVE-2024-48892


JSON object : View

Products Affected

fortinet

  • fortisoar
CWE
CWE-23

Relative Path Traversal