CVE-2022-26121
LOWFortiAnalyzer FortiManager GUI <7.0.4 - Info Disclosure
Title source: llmDescription
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
References (1)
Scores
CVSS v3
3.7
EPSS
0.0018
EPSS Percentile
39.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-668
Status
published
Affected Products (2)
fortinet/fortimanager
< 5.6.11
fortinet/fortianalyzer
< 5.6.11
Timeline
Published
Oct 10, 2022
Tracked Since
Feb 18, 2026