Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-36172

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.7%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 6.4
Products affected by CVE-2021-36172


Contact Us

Shodan ® - All rights reserved