PT-2021-21163 · Fortinet · Fortiportal

Published

2021-11-02

·

Updated

2021-11-04

·

CVE-2021-36181

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiPortal versions prior to 6.0.6
Description The issue is related to a concurrent execution using shared resources with improper synchronization, also known as a 'Race Condition', in the customer database interface. This may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent state via specific coordination of web requests.
Recommendations For versions prior to 6.0.6, update to version 6.0.6 or later to resolve the issue.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36181

Affected Products

Fortiportal