{"id":"CVE-2021-3378","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-3378","summary":"FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a \"Content-Type: image/png\" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.","details":"FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a \"Content-Type: image/png\" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.","published":"2021-02-01T22:08:33.000Z","modified":"2024-08-03T16:53:17.416Z","cvss":null,"epss":{"score":0.97512,"percentile":0.99896,"asOf":"2026-09-04"},"cisaKev":null,"exploitsKnown":7,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/erberkan/fortilogger_arbitrary_fileupload"},{"type":"WEB","url":"http://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-03T16:53:17.416Z"}}