Analyse sur rafaelpfister.ch

Description de l'éditeur (en anglais)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Données de référence

Éditeur
Fortinet
Produits concernés
  • FortiMail
CVSS 3.1
9.8 (CRITICAL)
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Type de faiblesse
CWE-22: Path Traversal
Publiée
1 octobre 2026
Dans le catalogue KEV depuis
1 octobre 2026
Échéance administrations fédérales US
4 octobre 2026

Sources officielles

← Toutes les vulnérabilités