A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.
2021-08-04T15:15:09.117
2024-11-21T06:13:14.660
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiportal | < 5.2.6 | Yes |
Application | fortinet | fortiportal | < 5.3.6 | Yes |
Application | fortinet | fortiportal | < 6.0.5 | Yes |