FortiSIEM – multiple path traversal vulnerabilities

Fortiguard Security Advisory

A relative path traversal vulnerability [CWE-23] in FortiSIEM file upload components may allow an authenticated, low privileged user of the FortiSIEM GUI to escalate their privilege and replace arbitrary files on the underlying filesystem via specifically crafted HTTP requests.

READ MORE