Security Advisory

CVE-2021-36168

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-08-04 15:01:20
Last updated 2024-10-25 13:53:28
Assigner fortinet
State PUBLISHED

Description

A Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.