A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiportal | Fortinet | 7.0.0 (including) | 7.0.6 (including) |
Fortiportal | Fortinet | 7.2.0 (including) | 7.2.0 (including) |
Fortiportal | Fortinet | 7.2.1 (including) | 7.2.1 (including) |