Loading HuntDB...

GHSA-mhr4-7gpq-rjpw

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] in Fortinet FortiADCManager version 7.1.0 and before 7.0.0, FortiADC version 7.2.0 and before 7.1.2 allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests.

Related CVEs

Key Information

GHSA ID
GHSA-mhr4-7gpq-rjpw
Published
June 13, 2023 9:30 AM
Last Modified
April 4, 2024 4:45 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.