OS Command Injection in FortiTester - CVE-2023-36642
Published: September 27, 2023
FortiTester
Fortinet, Inc
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper input validation in FortiGuard explicit proxy setting within the management interface of FortiTester. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.