OS Command Injection in FortiExtender - CVE-2019-15710
Published: October 29, 2019 / Updated: November 1, 2019
FortiExtender
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insufficient processing of user supplied input within the FortiExtender CLI. A remote authenticated user can inject and execute arbitrary system level commands via a specially crafted "execute date" command.