Security Advisory

CVE-2024-48890

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-01-14 14:09:50
Last updated 2025-01-15 14:55:00
Assigner fortinet
CVSS score 6.3
State PUBLISHED

Description

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook