CVE-2021-24013

CWE-22Path Traversal4 documents4 sources
Severity
6.5MEDIUM
EPSS
0.6%
top 30.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateMay 24

Description

Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortimail6.0.06.0.11+3
CVEListV5fortinet/fortinet_fortimailFortiMail before 6.4.4

🔴Vulnerability Details

2
GHSA
GHSA-43fc-qcr8-6g6r: Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 62022-05-24
CVEList
CVE-2021-24013: Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 62021-07-12

📋Vendor Advisories

1
Fortinet
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unau...2021-07-12
CVE-2021-24013 (MEDIUM CVSS 6.5) | Multiple Path traversal vulnerabili | cvebase.io