First published: Tue Nov 02 2021(Updated: )
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent state via specific coordination of web requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | >=4.0.0<6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-36181.
The title of this vulnerability is 'A concurrent execution using shared resource with improper Synchronization vulnerability (Race Condition).'
The severity of CVE-2021-36181 is low with a CVSS score of 3.1.
The affected software is FortiPortal versions before 6.0.6.
An authenticated, low-privilege user can exploit CVE-2021-36181 by manipulating the customer database interface to bring the underlying database data into an inconsistent state.