imPC@ndo IT

Tracker / CVE-2020-29018

CVE-2020-29018

High 8.8

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

Affected products and versions

fortinet fortiweb · 6.3.0 → 6.3.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References