Unrestricted File Upload Vulnerability in FortiPortal by Fortinet
CVE-2021-32594

5.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
4 August 2021

Summary

An unrestricted file upload vulnerability in the web interface of FortiPortal allows low-privileged users to upload maliciously crafted files, potentially enabling them to manipulate critical system files and compromise the integrity of the FortiPortal environment. This vulnerability affects various versions of FortiPortal, making it crucial for users to apply necessary security patches and implement strict file upload controls to mitigate potential risks.

Affected Version(s)

Fortinet FortiPortal FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.