CVE-2025-25254
08.04.2025, 14:15
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.| Vendor | Product | Version |
|---|---|---|
| fortinet | fortiweb | 7.0.0 ≤ 𝑥 < 7.4.7 |
| fortinet | fortiweb | 7.6.0 ≤ 𝑥 < 7.6.3 |
𝑥
= Vulnerable software versions