RULE(RULE ID:333417)

Rule General Information
Release Date: 2021-04-07
Rule Name: FortiLogger Arbitrary File Upload Vulnerability (CVE-2021-3378)
Severity:
CVE ID:
Rule Protection Details
Description: FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows
Reference: http://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html
http://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html
https://github.com/erberkan/fortilogger_arbitrary_fileupload
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.fortilogger.com/