Multiple authenticated OS Command Injections via API

0
15

CVSSv3 Score: 6.7

An OS command injection vulnerabtility [CWE-78] in FortiExtender API may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

Revised on 2025-12-09 00:00:00

– Read more