漏洞描述
FortiLogger 4.4.2.2 is affected by arbitrary file upload issues. Attackers can send a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then Assets/temp/hotspot/img/logohotspot.asp.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
erberkan.github.iohttps://erberkan.github.io/2021/cve-2021-3378/↗github.comhttps://github.com/erberkan/fortilogger_arbitrary_fileupload↗packetstormsecurity.comhttp://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html↗