CVE-2021-3378
Summary
| CVE | CVE-2021-3378 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-01 23:15:00 UTC |
| Updated | 2021-03-31 12:56:00 UTC |
| Description | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GitHub - erberkan/fortilogger_arbitrary_fileupload |
MISC |
github.com |
Exploit, Third Party Advisory |
| FortiLogger Arbitrary File Upload ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| FortiLogger 4.4.2.2 Arbitrary File Upload ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375651 FortiLogger Unauthenticated Arbitrary File Upload Vulnerability.
- 730101 FortiLogger Unauthenticated Arbitrary File Upload Vulnerability.