An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.
2021-08-04T14:15:08.257
2024-11-21T06:07:20.563
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiportal | ≤ 4.0.4 | Yes |
Application | fortinet | fortiportal | ≤ 4.1.2 | Yes |
Application | fortinet | fortiportal | ≤ 4.2.4 | Yes |
Application | fortinet | fortiportal | ≤ 5.0.3 | Yes |
Application | fortinet | fortiportal | ≤ 5.1.2 | Yes |
Application | fortinet | fortiportal | < 5.2.6 | Yes |
Application | fortinet | fortiportal | < 5.3.6 | Yes |
Application | fortinet | fortiportal | < 6.0.5 | Yes |