Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiportal  >> 7.0.2  Security Vulnerabilities
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
CVSS Score
7.2
EPSS Score
0.002
Published
2024-01-10
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
CVSS Score
5.4
EPSS Score
0.003
Published
2024-01-10
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
CVSS Score
8.8
EPSS Score
0.034
Published
2023-12-13
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-02-16


Contact Us

Shodan ® - All rights reserved