CVE-2023-23784: Fortinet FortiWeb

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.

Affected products

  • Fortinet FortiWeb: from 6.3.6, before 6.3.21 (fixed in 6.3.21); from 6.4.0, up to and including 6.4.2; from 7.0.0, before 7.0.3 (fixed in 7.0.3)

Published 2023-02-16. Last modified 2026-06-17.