{"id":67936,"date":"2025-08-12T23:32:19","date_gmt":"2025-08-12T20:02:19","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-52970-fortinet-fortiweb-unauthenticated-privilege-escalation-vulnerability\/"},"modified":"2025-08-12T23:32:19","modified_gmt":"2025-08-12T20:02:19","slug":"cve-2025-52970-fortinet-fortiweb-unauthenticated-privilege-escalation-vulnerability","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-52970-fortinet-fortiweb-unauthenticated-privilege-escalation-vulnerability\/","title":{"rendered":"CVE-2025-52970 &#8211; Fortinet FortiWeb Unauthenticated Privilege Escalation Vulnerability"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-52970<br \/>\n<br \/>\n<strong>Published : <\/strong> Aug. 12, 2025, 7:15 p.m. | 30\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 8.1 | HIGH<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-52970 Published : Aug. 12, 2025, 7:15 p.m. | 30\u00a0minutes ago Description : A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-67936","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/67936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=67936"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/67936\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=67936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=67936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=67936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}