27/09/2025
ZDI-25-918: Fortinet FortiWeb _cmf_get_config_file_path Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fortinet FortiWeb. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2025-53609.
Comments are closed.