VYPR
High severity7.2NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026

CVE-2016-8494

CVE-2016-8494

Description

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

Affected products

5
  • Fortinet/Connect4 versions
    cpe:2.3:a:fortinet:connect:14.10:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:connect:14.10:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:connect:14.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:connect:15.10:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:connect:16.7:*:*:*:*:*:*:*
  • Fortinet/Fortinet Connectv5
    Range: 14.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.