Show filters
874 Total Results
Displaying 151-160 of 874
Sort by:
Attacker Value
Unknown
CVE-2024-23667
Disclosure Date: June 03, 2024 (last updated December 18, 2024)
An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
0
Attacker Value
Unknown
CVE-2024-23665
Disclosure Date: June 03, 2024 (last updated December 18, 2024)
Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.
0
Attacker Value
Unknown
CVE-2024-23664
Disclosure Date: June 03, 2024 (last updated January 22, 2025)
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
0
Attacker Value
Unknown
CVE-2024-31493
Disclosure Date: June 03, 2024 (last updated January 22, 2025)
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
0
Attacker Value
Unknown
CVE-2024-23107
Disclosure Date: June 03, 2024 (last updated December 18, 2024)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
0
Attacker Value
Unknown
CVE-2023-48789
Disclosure Date: June 03, 2024 (last updated January 07, 2025)
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2024-31491
Disclosure Date: May 14, 2024 (last updated January 06, 2025)
A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
0
Attacker Value
Unknown
CVE-2024-31488
Disclosure Date: May 14, 2024 (last updated January 22, 2025)
An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2024-26007
Disclosure Date: May 14, 2024 (last updated December 21, 2024)
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2024-23105
Disclosure Date: May 14, 2024 (last updated May 24, 2024)
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
0