Unrestricted File Upload Vulnerability in FortiPortal by Fortinet
CVE-2021-32594
5.4MEDIUM
What is CVE-2021-32594?
An unrestricted file upload vulnerability in the web interface of FortiPortal allows low-privileged users to upload maliciously crafted files, potentially enabling them to manipulate critical system files and compromise the integrity of the FortiPortal environment. This vulnerability affects various versions of FortiPortal, making it crucial for users to apply necessary security patches and implement strict file upload controls to mitigate potential risks.
Affected Version(s)
Fortinet FortiPortal FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier