QID 378069
Date Published: 2023-03-23
QID 378069: Fortinet FortiAnalyzer CSV injection Vulnerability (FG-IR-22-488)
An improper neutralization of formula elements vulnerability in FortiAnalyzer may allow a local authenticated privileged attacker to execute arbitrary code on the end-user's host via inserting spreadsheet formulas in the macro names
Affected Products:
FortiAnalyzer version 7.2.0 through 7.2.1
FortiAnalyzer version 7.0.0 through 7.0.6
FortiAnalyzer 6.4 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAnalyzer.
Successful exploitation may allow a local authenticated privileged attacker to execute arbitrary code
Solution
Vendor has released fixes to address this vulnerability
For more details please refer advisory FG-IR-22-488
Vendor References
- FG-IR-22-488 -
www.fortiguard.com/psirt/FG-IR-22-488
CVEs related to QID 378069
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-488 |
|