An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-115 | Vendor Advisory |
Configurations
History
22 Jul 2025, 21:22
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet fortiweb
Fortinet |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-115 - Vendor Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
11 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-11 15:15
Updated : 2025-07-22 21:22
NVD link : CVE-2023-42784
Mitre link : CVE-2023-42784
CVE.ORG link : CVE-2023-42784
JSON object : View
Products Affected
fortinet
- fortiweb
CWE
CWE-228
Improper Handling of Syntactically Invalid Structure