A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-463 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-01-14 14:15
Updated : 2026-01-14 13:16
NVD link : CVE-2024-50566
Mitre link : CVE-2024-50566
CVE.ORG link : CVE-2024-50566
JSON object : View
Products Affected
fortinet
- fortimanager_cloud
- fortimanager
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
