CVE-2020-29018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
14/01/2021
Last modified:
20/01/2021

Description

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.3.0 (including) 6.3.5 (including)


References to Advisories, Solutions, and Tools