First published: Wed Aug 04 2021(Updated: )
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | <5.2.6 | |
Fortinet FortiPortal | >=5.3.0<5.3.6 | |
Fortinet FortiPortal | >=6.0.0<6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36168 is a vulnerability in Fortinet FortiPortal that allows an authenticated attacker to disclose information through a crafted GET request with malicious parameter values.
The severity of CVE-2021-36168 is medium with a CVSS score of 6.5.
Fortinet FortiPortal 5.2.6, 5.3.x (up to 5.3.6), and any version before 6.2.5 are affected by CVE-2021-36168.
An attacker can exploit CVE-2021-36168 by sending a crafted GET request with malicious parameter values.
Yes, Fortinet FortiPortal version 6.0.5, 5.3.6, and 6.2.5 onwards have addressed the vulnerability CVE-2021-36168.