imPC@ndo IT

Tracker / CVE-2021-32594

CVE-2021-32594

Medium 5.4

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.

Affected products and versions

fortinet fortiportal · 4.0.0 → 4.0.4
fortinet fortiportal · 4.1.0 → 4.1.2
fortinet fortiportal · 4.2.0 → 4.2.4
fortinet fortiportal · 5.0.0 → 5.0.3
fortinet fortiportal · 5.1.0 → 5.1.2
fortinet fortiportal · 5.2.0 → 5.2.6
fortinet fortiportal · 5.3.0 → 5.3.6
fortinet fortiportal · 6.0.0 → 6.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References