ID:8857 - Exploit for External Control of File Name or Path in FortiNAC - CVE-2022-39952
Published: February 21, 2023
FortiNAC
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to application allows an attacker to control path of the files to write within the keyUpload scriptlet. A remote non-authenticated attacker can send a specially crafted HTTP request and upload arbitrary files to the system.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.