CVE-2024-48892

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a

Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.004
33.1th percentile
Discovered by
Not disclosed
Published
Aug 12, 2025
Assigned by fortinet

Description

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.

Weakness: CWE-23

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiSOAR

Vendor remediation

Please upgrade to FortiSOAR version 7.6.1 or above Please upgrade to FortiSOAR version 7.5.2 or above