A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortimanager | 7.4.0 | 7.4.3 |
| fortinet / fortimanager | 7.0.0 | 7.2.6 |