back to article Researchers find high-severity command injection vuln in Fortinet's web app firewall

A command injection vulnerability exists in Fortinet's management interface for its FortiWeb web app firewall, according to infosec firm Rapid7. An authenticated attacker can use the vuln to execute commands as root on the Fortiweb device, Rapid7 said in a blog post. By using backticks "in the 'name' field of the SAML Server …

