QID 375651
Date Published: 2021-06-24
QID 375651: FortiLogger Unauthenticated Arbitrary File Upload Vulnerability.
FortiLogger is a web-based logging and reporting software that runs on Windows operating systems, specially prepared for FortiGate firewalls. It includes features such as instant status tracking, logging, search/filtering, reporting and hotspot.
Affected Products
FortiLogger 4.4.2.2.
QID Detection Logic (Authenticated):
QID will check the version of fortiloggerservice.exe
Successful exploits could lead to an unauthenticated arbitrary file upload via insecure POST request.
Vendor References
- CVE-2021-3378 -
github.com/erberkan/fortilogger_arbitrary_fileupload
CVEs related to QID 375651
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| fortilogger |
|