Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-21759

Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Attacker Value
Unknown

CVE-2024-31495

Disclosure Date: June 11, 2024 (last updated January 07, 2025)
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
Attacker Value
Unknown

CVE-2024-23105

Disclosure Date: May 14, 2024 (last updated May 24, 2024)
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
Attacker Value
Unknown

CVE-2024-21761

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Attacker Value
Unknown

CVE-2023-48791

Disclosure Date: December 13, 2023 (last updated December 16, 2023)
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.