CVE-2024-52964
12.08.2025, 19:15
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortimanager | 6.2.0 ≤ 𝑥 < 7.0.14 |
fortinet | fortimanager | 7.2.0 ≤ 𝑥 < 7.2.10 |
fortinet | fortimanager | 7.4.0 ≤ 𝑥 < 7.4.6 |
fortinet | fortimanager | 7.6.0 ≤ 𝑥 < 7.6.2 |
fortinet | fortimanager_cloud | 6.4.1 ≤ 𝑥 ≤ 7.0.13 |
fortinet | fortimanager_cloud | 7.2.1 ≤ 𝑥 < 7.2.10 |
fortinet | fortimanager_cloud | 7.4.1 ≤ 𝑥 < 7.4.6 |
𝑥
= Vulnerable software versions