Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiportal  >> 7.2.2  Security Vulnerabilities
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal System Log.
CVSS Score
2.3
EPSS Score
0.0
Published
2025-05-28
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-01-14


Contact Us

Shodan ® - All rights reserved