CVE-2021-36168 Information
Jun 07, 2022
cve
Description
A Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) in Fortinet FortiPortal 6.x before 6.0.5 FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://fortiguard.com/advisory/FG-IR-21-085
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: