Security Advisory
CVE-2021-36168
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.