A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortiportal | 7.0.0 | 7.0.6.x |
| fortinet / fortiportal | 7.2.0 | 7.2.0.x |
| fortinet / fortiportal | 7.2.1 | 7.2.1.x |