CVE-2022-22297
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versions 6.0, FortiRecorder all versions 2.7 may allow an authenticated user to read arbitrary files via specially crafted command arguments.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C
- EPSS probability
- 0.07%
- CWE
- CWE-792
- Published
- 2023-03-07
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiRecorder
- Fortinet FortiRecorder
- Fortinet FortiRecorder
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
Weakness type
Related vulnerabilities
- CVE-2025-12758 — Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or...
- CVE-2025-47779 — Using malformed From header can forge identity with ";" or NULL in name portion
- CVE-2023-25608 — An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the...
- CVE-2023-20057 — A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security...