All intelligence
// vulnerability record
live · NVDCVE-2023-42784
MEDIUMpublished 2025-03-11 15:15 UTC · 1 year ago · modified 2026-06-17 06:24 UTC
5.6
CVSS / 10
// description
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
// cvss 3.1 vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
// weaknesses (CWE)
- CWE-228