Outbreak Alert: SolarView Compact Command Injection Vulnerability
| Description | In CVE-2022-29303, a command injection vulnerability in SolarView Compact version 6.00, discovered via conf_mail.php.
In CVE-2022-40881, a command injection vulnerability in SolarView Compact version 6.00, discovered via network_test.php.
This article describes the assessment of command injection vulnerability in SolarView Compact. |
| Scope | FortiDAST Scripting Engine updated in version 24.2.0 |
| Solution | Detection against that vulnerability is empowered by the FortiDAST Scripting Engine (FSE).
For reference, a step-by-step guide on how to configure FortiDAST to trigger FSE can be found on Fortinet’s blog: |
