Vulnerability Details CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.0%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-36168
-
cpe:2.3:a:fortinet:fortiportal:-
-
cpe:2.3:a:fortinet:fortiportal:2.3.0
-
cpe:2.3:a:fortinet:fortiportal:2.3.1
-
cpe:2.3:a:fortinet:fortiportal:3.2.0
-
cpe:2.3:a:fortinet:fortiportal:3.2.1
-
cpe:2.3:a:fortinet:fortiportal:3.2.2
-
cpe:2.3:a:fortinet:fortiportal:4.0.0
-
cpe:2.3:a:fortinet:fortiportal:4.0.1
-
cpe:2.3:a:fortinet:fortiportal:4.0.2
-
cpe:2.3:a:fortinet:fortiportal:4.0.3
-
cpe:2.3:a:fortinet:fortiportal:4.0.4
-
cpe:2.3:a:fortinet:fortiportal:4.1.0
-
cpe:2.3:a:fortinet:fortiportal:4.1.1
-
cpe:2.3:a:fortinet:fortiportal:4.1.2
-
cpe:2.3:a:fortinet:fortiportal:4.2.0
-
cpe:2.3:a:fortinet:fortiportal:4.2.1
-
cpe:2.3:a:fortinet:fortiportal:4.2.2
-
cpe:2.3:a:fortinet:fortiportal:4.2.3
-
cpe:2.3:a:fortinet:fortiportal:4.2.4
-
cpe:2.3:a:fortinet:fortiportal:5.0.0
-
cpe:2.3:a:fortinet:fortiportal:5.0.1
-
cpe:2.3:a:fortinet:fortiportal:5.0.2
-
cpe:2.3:a:fortinet:fortiportal:5.0.3
-
cpe:2.3:a:fortinet:fortiportal:5.1.0
-
cpe:2.3:a:fortinet:fortiportal:5.1.1
-
cpe:2.3:a:fortinet:fortiportal:5.1.2
-
cpe:2.3:a:fortinet:fortiportal:5.2.0
-
cpe:2.3:a:fortinet:fortiportal:5.2.1
-
cpe:2.3:a:fortinet:fortiportal:5.2.2
-
cpe:2.3:a:fortinet:fortiportal:5.2.3
-
cpe:2.3:a:fortinet:fortiportal:5.2.4
-
cpe:2.3:a:fortinet:fortiportal:5.2.5
-
cpe:2.3:a:fortinet:fortiportal:5.3.0
-
cpe:2.3:a:fortinet:fortiportal:5.3.1
-
cpe:2.3:a:fortinet:fortiportal:5.3.2
-
cpe:2.3:a:fortinet:fortiportal:5.3.3
-
cpe:2.3:a:fortinet:fortiportal:5.3.4
-
cpe:2.3:a:fortinet:fortiportal:5.3.5
-
cpe:2.3:a:fortinet:fortiportal:6.0.0
-
cpe:2.3:a:fortinet:fortiportal:6.0.1
-
cpe:2.3:a:fortinet:fortiportal:6.0.2
-
cpe:2.3:a:fortinet:fortiportal:6.0.3
-
cpe:2.3:a:fortinet:fortiportal:6.0.4