CVE-2024-48892

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a

Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.004
34.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2025
Assigned by fortinet

Description

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.

Weakness: CWE-23

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSOAR

Credit

Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSOAR version 7.6.1 or above Please upgrade to FortiSOAR version 7.5.2 or above

Something wrong here?