Vulnerability Details CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 61.4%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-36168
-
cpe:2.3:a:fortinet:fortiportal:-
-
cpe:2.3:a:fortinet:fortiportal:2.3.0
-
cpe:2.3:a:fortinet:fortiportal:2.3.1
-
cpe:2.3:a:fortinet:fortiportal:3.2.0
-
cpe:2.3:a:fortinet:fortiportal:3.2.1
-
cpe:2.3:a:fortinet:fortiportal:3.2.2
-
cpe:2.3:a:fortinet:fortiportal:4.0.0
-
cpe:2.3:a:fortinet:fortiportal:4.0.1
-
cpe:2.3:a:fortinet:fortiportal:4.0.2
-
cpe:2.3:a:fortinet:fortiportal:4.0.3
-
cpe:2.3:a:fortinet:fortiportal:4.0.4
-
cpe:2.3:a:fortinet:fortiportal:4.1.0
-
cpe:2.3:a:fortinet:fortiportal:4.1.1
-
cpe:2.3:a:fortinet:fortiportal:4.1.2
-
cpe:2.3:a:fortinet:fortiportal:4.2.0
-
cpe:2.3:a:fortinet:fortiportal:4.2.1
-
cpe:2.3:a:fortinet:fortiportal:4.2.2
-
cpe:2.3:a:fortinet:fortiportal:4.2.3
-
cpe:2.3:a:fortinet:fortiportal:4.2.4
-
cpe:2.3:a:fortinet:fortiportal:5.0.0
-
cpe:2.3:a:fortinet:fortiportal:5.0.1
-
cpe:2.3:a:fortinet:fortiportal:5.0.2
-
cpe:2.3:a:fortinet:fortiportal:5.0.3
-
cpe:2.3:a:fortinet:fortiportal:5.1.0
-
cpe:2.3:a:fortinet:fortiportal:5.1.1
-
cpe:2.3:a:fortinet:fortiportal:5.1.2
-
cpe:2.3:a:fortinet:fortiportal:5.2.0
-
cpe:2.3:a:fortinet:fortiportal:5.2.1
-
cpe:2.3:a:fortinet:fortiportal:5.2.2
-
cpe:2.3:a:fortinet:fortiportal:5.2.3
-
cpe:2.3:a:fortinet:fortiportal:5.2.4
-
cpe:2.3:a:fortinet:fortiportal:5.2.5
-
cpe:2.3:a:fortinet:fortiportal:5.3.0
-
cpe:2.3:a:fortinet:fortiportal:5.3.1
-
cpe:2.3:a:fortinet:fortiportal:5.3.2
-
cpe:2.3:a:fortinet:fortiportal:5.3.3
-
cpe:2.3:a:fortinet:fortiportal:5.3.4
-
cpe:2.3:a:fortinet:fortiportal:5.3.5
-
cpe:2.3:a:fortinet:fortiportal:6.0.0
-
cpe:2.3:a:fortinet:fortiportal:6.0.1
-
cpe:2.3:a:fortinet:fortiportal:6.0.2
-
cpe:2.3:a:fortinet:fortiportal:6.0.3
-
cpe:2.3:a:fortinet:fortiportal:6.0.4