About FortiWLM 8.6.6
This release of FortiWLM delivers the following modifications along with resolving outstanding issues. See sections Fixed Issues and Common Vulnerabilities and Exposures.
-
With this release, Shell In A Box is disabled on FortiWLM.
-
When you access the FortiWLC CLI from FortiWLM and Shell In A Box is enabled on FortiWLC, then you are exposed to the vulnerability, CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
-
Run the
webshell disable
command to disable Shell In A Box in FortiWLC.