Medium SEVERITY — Vulnerability

Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
6.2/10
Advisory
FG-IR-26-115
Published
14 April 2026
Views
5
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Özet

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

Kaynak

Bu kayıt otomatik olarak içeri alınmıştır; yayına almadan önce içeriği doğrulayın.

FortiGate / FortiOS — Related Advisories

VIEW ALL →